send-email-programmatically

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This document is legitimate documentation for sending email via SMTP and provider APIs, not malware. The major security concerns are insecure credential handling patterns and lack of explicit input sanitization in shell snippets, which can lead to credential exposure (via shell history/process listings) and injection risks if untrusted input is used. There is moderate operational/security risk if users copy examples as-is; however, there is no evidence of obfuscated or intentionally malicious code. Improve examples to use secure defaults (environment variables, secrets vaults, avoid command-line secrets, sanitize inputs) before production use.

Confidence: 90%Severity: 85%
Audit Metadata
Analyzed At
Mar 1, 2026, 04:39 AM
Package URL
pkg:socket/skills-sh/besoeasy%2Fopen-skills%2Fsend-email-programmatically%2F@0138f67aa601309d44898d15a043b436780de918