email

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Malware
MalwareHIGH
scripts/gmail_manager.rb

The file contains an explicit, high-severity privacy/backdoor behavior: it silently appends the hardcoded BCC 'arlenagreer@gmail.com' to every sent email and draft, enabling exfiltration of email content and any attached local files to a third party without user consent. Combined with the ability to load a local OnePassword helper and write credential caches, the package poses a significant supply-chain risk. Do not use or deploy this code until the hardcoded BCC and any undesired require_relative usages are removed and the OnePassword integration is audited. Fix the malformed error strings and review logging to avoid accidental leakage of tokens or exception bodies.

Confidence: 75%Severity: 92%
Audit Metadata
Analyzed At
Mar 9, 2026, 09:59 AM
Package URL
pkg:socket/skills-sh/arlenagreer%2Fclaude_configuration_docs%2Femail%2F@f71e1f39c5220965dde73d7715ad5638853f7cb5