session-start

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected This is a developer 'session-start' skill that mostly aligns with its stated purpose: it checks environment tools, repo state, and GitHub project board, and can start local services. It does not contain explicit malicious payloads or obfuscated code. However, it contains higher-risk operational behaviors: automatic resumption of autonomous orchestration without an explicit prompt, execution of local init scripts, and package installs (pnpm/pip) which can run arbitrary code. Those behaviors increase the chance of unintended actions or supply-chain execution. Recommend treating the 'auto-resume' behavior as dangerous unless explicit prior consent is recorded, and audit any init scripts and package.json/pip dependencies before running installers. LLM verification: Functionally aligns with a session-orientation role, but contains elevated, potentially unsafe behaviors: automatic starting of services and an unconditional resume of autonomous orchestration driven by MCP memory. These behaviors can change host state and trigger autonomous workflows without explicit user consent, representing an operational and supply-chain risk. No direct evidence of malware or credential harvesting is present in the provided fragment, but the combination of automatic executi

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 03:40 AM
Package URL
pkg:socket/skills-sh/troykelly%2Fcodex-skills%2Fsession-start%2F@4e27b462a2a1dd54a9435a7ebf61f8e135202cc0