developer-growth-analysis

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's functionality (reading local chat history and delivering a personalized report to Slack) is plausible and not inherently malicious. The primary security concern is the ambiguous use of external Rube MCP tooling without documented execution boundaries, lack of required redaction of pastedContents, and unspecified OAuth/token handling. These omissions create a realistic risk of accidental data exfiltration of sensitive chat contents or credentials. No explicit malware was observed in the spec, but treat this module as high-risk until Rube MCP's hosting, data handling, and sanitization/consent controls are documented and implemented.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:02 PM
Package URL
pkg:socket/skills-sh/davila7%2Fclaude-code-templates%2Fdeveloper-growth-analysis%2F@b7172297fbe76d7ea320eb7a889202e8525fb81b