fireflies-observability

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Fireflies Observability skill appears coherent with its stated purpose: it monitors Fireflies.ai operations using the provided GraphQL API, computes metrics, and surfaces them through dashboards and alerts. The security footprint is minimal and aligned with typical monitoring tooling: it uses an environment-provided API key, calls the official API endpoint, and emits telemetry data to standard monitoring channels. There are no evident payloads that download executables, no credential forwarding to third-party binaries, and no suspicious data exfiltration patterns. As a precaution, ensure the FIREFLIES_API_KEY is managed with proper rotation and least-privilege access, and confirm that the telemetry sinks are secured and access-controlled. Overall risk assessment: Benign to Low risk with normal observability patterns; consider tracking rotation/credential scope and ensuring logs do not reveal sensitive transcript content beyond what is appropriate for monitoring.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 05:48 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Ffireflies-observability%2F@f7c76fd3ade0dc5b63e08c3b72189758f692e7c1