session-reset

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md describes a session-reset workflow that is coherent with its stated purpose: saving a small ephemeral session summary (PROMPT.md), optionally committing safe work, tearing down an active agent team, and guiding the user to /clear and restore. I found no download-execute supply-chain patterns, no obfuscated or hidden code, and no direct credential harvesting instructions. The main risks are operational: it performs potentially destructive or sensitive actions (git commit/push, sending shutdown_request, TeamDelete) and reads team configuration files which may be sensitive. These actions are plausible for a session-management skill but require strong interactive user confirmations and appropriate permission controls. Overall this appears functionally appropriate for its purpose, but it is moderately privileged and should only be allowed when users explicitly approve each impactful operation.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:06 PM
Package URL
pkg:socket/skills-sh/webbertakken%2Fagent-skills%2Fsession-reset%2F@50f0c3d0ed4c4d8ef1e246a19714b6c8be3278ba