clerk-data-handling

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Clerk Data Handling skill is broadly coherent with its stated purpose to support GDPR/privacy workflows (export, deletion, retention, consent, audit). The data flows and access scope are largely proportional to the tasks, and the use of Clerk DB and an optional external audit endpoint is reasonable. The main concerns are potential data exfiltration risk from an optional external audit POST, a minor inconsistency in getConsent (uses currentUser vs. provided userId), and a placeholder for external service deletions that could become a real integration risk if not implemented securely. Overall, the footprint is mostly benign with moderate security considerations requiring proper safeguards around the external audit endpoint and authorization alignment.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 06:43 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fclerk-data-handling%2F@642545d7a697dc92ac5e1e257684c7e69fa4ecbb