em-capture-idea

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill's stated purpose (collect and save research material into an Obsidian Inbox) aligns with most of its capabilities: reading a local config, invoking a local Twitter/X CLI, and writing markdown files are proportionate to the function. The primary security concerns are operational rather than covert malware: (1) it executes a third-party CLI (bird) using the user's existing credentials and performs destructive operations (bird unbookmark) which modify the user's account; (2) it writes files into the user's Obsidian vault and includes remote embeds which can leak metadata when notes are opened; (3) it instructs installing third-party tooling via Homebrew, which is a supply-chain action. There is no evidence of obfuscation, hidden network exfiltration to attacker-controlled endpoints, or embedded malicious payloads. Overall the skill is functionally coherent but carries moderate security/privacy risk due to destructive account actions and file/network effects. Recommend clearly prompting for per-item confirmation before running unbookmark, documenting privacy implications of remote embeds, and ensuring the user explicitly consents to installation/execution of the bird CLI.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 09:20 AM
Package URL
pkg:socket/skills-sh/easymailing%2Feasymailing-skills%2Fem-capture-idea%2F@113f0ef1c5bbf2d1dde9542c2bb4c3d498a7febe