note-draft

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's described capabilities (drafting posts to note.com via API or Playwright, handling images, and optional header image) align with its stated purpose. Credential handling is standard for a tool integration but concentrates sensitive data in environment variables (.env). Download/installation are performed from official registries (npm, Playwright), not unverified binaries. Data flows mainly to note.com services with content and images; no clear evidence of credential forwarding to third-party services. Overall risk profile is moderate with no evident malicious intent, but credential exposure and browser automation introduce typical security considerations. Recommend ensuring secure handling of .env, providing a simulated mode for testing without real credentials, and documenting credential rotation and least-privilege practices.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 11:13 PM
Package URL
pkg:socket/skills-sh/anyoneanderson%2Fnote-md-publisher%2Fnote-draft%2F@c447b81ad290fec2da64339c52c49f234e9a48b8