chief-of-staff
Fail
Audited by Socket on Mar 14, 2026
1 alert found:
Obfuscated FileObfuscated File.claude/commands/generate-newsletter-digest.md
HIGHObfuscated FileHIGH
.claude/commands/generate-newsletter-digest.md
No direct signs of executable malware or obfuscation in the workflow text itself. The main security concern is deliberate exfiltration of sensitive local context and email content to an external API (hartreeworks.org) without documented redaction or minimization. Treat this as a privacy/supply-chain risk: only run if you trust the remote endpoint and the operators, minimize what is sent (remove PII, avoid including full message bodies and message IDs), and manage the API key securely.
Confidence: 98%
Audit Metadata