campaign-brief-generator

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No code-level malware patterns are present in the provided specification. The primary security concerns are data-flow and transitive trust: reading local brand-context files can leak sensitive data into creator-facing outputs; chaining to other skills increases the attack surface; and inclusion of arbitrary external links or user-supplied content may propagate malicious links or confidential information. Recommend: (1) restrict .claude/brand-context.md to non-sensitive fields and educate users not to store secrets there; (2) sanitize and validate external URLs and asset links before including them in briefs; (3) require explicit user confirmation before invoking or forwarding context to other skills; (4) treat any auto-populated 'Don'ts' as user-verified content and present a confirmation step prior to publishing creator-facing output.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 4, 2026, 06:37 PM
Package URL
pkg:socket/skills-sh/archive-dot-com%2Fcreator-marketing-skills%2Fcampaign-brief-generator%2F@59d63f954148ba4fd920b24d3addafd88a813283