daily-news

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core news-digest workflow is coherent, but the skill expands trust boundaries by auto-modifying global Claude config, executing an unpinned external MCP package, and routing some content access through Browser MCP using the user's logged-in browser state. Optional public deployment and repo creation are proportionate if explicitly approved, but the overall footprint is broader than a basic news summarizer and carries medium security risk.

Confidence: 82%Severity: 64%
Audit Metadata
Analyzed At
Mar 13, 2026, 04:04 AM
Package URL
pkg:socket/skills-sh/ZhanlinCui%2FUltimate-Agent-Skills-Collection%2Fdaily-news%2F@d3b0272244a8842b0431524e096c56b51d53f57f