opened-weekly-newsletter-writer

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core newsletter-writing purpose is coherent, and there is no clear malware or off-purpose exfiltration. The main risks are a custom unpublished HubSpot push script, raw `.env` secret loading, outdated/ambiguous HubSpot auth terminology, optional cross-skill expansion, and publish-capable social workflows that could act without enough approval boundaries.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 15, 2026, 02:00 AM
Package URL
pkg:socket/skills-sh/cdeistopened%2Fopened-vault%2Fopened-weekly-newsletter-writer%2F@0e3b899e3a2b9d38c94fe439657f82cc514e54cd