ai-news-collector

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The AI News Collector skill fragment is coherent with its stated purpose. It describes gathering recent AI-related content from public sources, filtering to the last 7 days, and producing a structured digest with source links. There are no credential requirements, no explicit self-modifying or download/install behavior, and data flows remain within read-only collection and reporting. As implemented, the security risk is low and the malware risk is negligible. Ensure implementation enforces 7-day limits, respects robots/crawling policies, and preserves source attribution in all outputs.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 07:16 AM
Package URL
pkg:socket/skills-sh/yugasun%2Fskills%2Fai-news-collector%2F@4481ad362d36074f080858169e34454055b6c58d