casualize-names

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The package implements a benign, clearly stated transformation (casualizing names for email personalization) and relies on a third-party LLM (Anthropic) to perform the transformation. There are no signs of obfuscated or explicitly malicious code in the provided description. The main security concerns are privacy and operational: PII (names, emails, companies) is read from Google Sheets and sent to a third-party API without documented minimization, and Google authentication handling is unspecified. Before use, the project should document Google auth requirements, ensure minimal data is sent to Anthropic, add logging/retention guidance, and provide secure secret-management recommendations to reduce accidental data exposure.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 6, 2026, 02:19 PM
Package URL
pkg:socket/skills-sh/aiagentwithdhruv%2Fskills%2Fcasualize-names%2F@e19e8c535295ca6d9e9769c794dab03f30710077