check-action-items-from-contact

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and presents a plausible, privacy-conscious workflow for extracting action items from emails. However, there are notable privacy and credential-management considerations: it reads user email data via Apple Mail, which is sensitive; it references credential placeholders for key-store usage, which could lead to insecure secret handling if not properly implemented. The overall design is coherent with its stated purpose but should enforce explicit user consent, least-privilege access, and clear secret-management practices to reduce risk.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 07:32 AM
Package URL
pkg:socket/skills-sh/dalehurley%2Fphpbot%2Fcheck-action-items-from-contact%2F@fd6a19d5431cd5bce6137b70fd5875aef1037a9d