instantly-autoreply

Fail

Audited by Socket on Mar 6, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The project implements expected functionality for automated reply generation, but its documented design contains significant privacy and secret-handling risks: storing credentials in a Google Sheet and sending KB content plus email threads to a third-party LLM without documented redaction or vaulting. There is no strong indicator of intentional malware or obfuscation in the provided description, but the data flows create moderate-to-high risk of accidental secret or PII leakage. Mitigations (remove credentials from KB, vault secrets, sanitize prompts, add review/safety controls, and secure logging) should be applied before use in production.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 6, 2026, 02:20 PM
Package URL
pkg:socket/skills-sh/aiagentwithdhruv%2Fskills%2Finstantly-autoreply%2F@2c6c32786b87fecc49c852073574e36fb3281d25