hr-automation

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The HR automation skill presents a coherent, purpose-aligned footprint: it automates recruiting, onboarding, time-off, performance reviews, and offboarding using established HR systems via documented workflow templates. The data flows and integrations are proportionate to its purpose, and there are no explicit download/executable payloads or unverifiable binaries. However, the description omits concrete credential management practices (how API keys/tokens are stored and rotated), detailed access controls, and data-minimization/privacy considerations for PII. The risk surface is moderate due to handling of sensitive HR data and privilege-provisioning steps; no external files or suspicious installations are evident. To improve, add explicit security controls (least-privilege scopes, vault-assisted credential management, audit logging, data retention policies) and concrete error/retry handling for API calls.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 08:22 AM
Package URL
pkg:socket/skills-sh/claude-office-skills%2Fskills%2Fhr-automation%2F@afa48fa2cce01740b8a777147662bd2bbf003825