email-unsubscribe-check

Warn

Audited by Socket on Feb 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill's stated purpose (inbox hygiene and unsubscribing) is plausible and many capabilities match the goal (reading mail, extracting unsubscribe links, creating filters). However, it contains multiple high‑risk operational patterns: automatic startup without an explicit kickoff prompt, programmatic retrieval and use of local credentials from 'pass', navigation of arbitrary unsubscribe URLs, and autonomous login + account changes on third‑party sites. These behaviors enable credential forwarding and broad remote state changes and therefore are security‑sensitive. I rate this skill as suspicious/high risk (not confirmed malware) — it needs stricter safeguards (explicit per‑scan consent, per‑site credential confirmation, domain whitelisting, validation of unsubscribe links, and clear audit/logging) before it should be run with access to a user's mailbox and password store.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Feb 22, 2026, 12:59 PM
Package URL
pkg:socket/skills-sh/colonelpanic8%2Fdotfiles%2Femail-unsubscribe-check%2F@e1ed04cc21c8c5183102e736dba27562701f2ab5