evernote-security-basics

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Evernote Security Basics skill presents a coherent security-focused approach to credential handling, OAuth, and token lifecycle with encryption and CSRF protections. The overall footprint aligns with its stated purpose, and the use of secret managers, environment variables, encrypted token storage, and input validation is appropriate. However, there are security concerns around session-based token storage (risk mitigated by HttpOnly/Secure cookies and proper session storage), potential over-reliance on multiple secret managers without clear governance, and a cryptographic key derivation approach that could be strengthened. Given these factors, the evaluation leans toward a moderate risk (suspicious-to-benign boundary), with concrete improvements recommended to reach a robust benign classification.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 02:01 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fevernote-security-basics%2F@728d4a34b00518b197aed03af85f72bcaa8ab7c8