chief-of-staff

Fail

Audited by Socket on Mar 14, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
.claude/commands/generate-newsletter-digest.md

No direct signs of executable malware or obfuscation in the workflow text itself. The main security concern is deliberate exfiltration of sensitive local context and email content to an external API (hartreeworks.org) without documented redaction or minimization. Treat this as a privacy/supply-chain risk: only run if you trust the remote endpoint and the operators, minimize what is sent (remove PII, avoid including full message bodies and message IDs), and manage the API key securely.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 14, 2026, 10:09 AM
Package URL
pkg:socket/skills-sh/hartreeworks%2Fskill--chief-of-staff%2Fchief-of-staff%2F@f9cce947d9cabe02c719242bf4aafe1bfd4a285f