triage

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The triage skill's behavior aligns with its stated purpose but carries moderate security risks because it performs destructive filesystem operations driven by user-provided strings with no described sanitization, confirmation, or sandboxing. There is no evidence of remote exfiltration or credential harvesting in the provided fragment. Recommended mitigations before deployment: restrict the agent to a sandboxed todos/ directory, implement strict filename/path sanitization and normalization, require explicit confirmations (or a two-step approval) before deletions, implement safe rename semantics and backups (move to a trash folder instead of immediate delete), and document minimal permission requirements for host agents.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 3, 2026, 11:54 AM
Package URL
pkg:socket/skills-sh/udecode%2Fplate%2Ftriage%2F@1d45df3c47071eabea72fafb0931098ff77359ca