contacts

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The described approach is coherent for an internal, vault-backed contact management and enrichment workflow. It is not inherently malicious and is appropriate for tightly controlled environments, but to reduce privacy and data governance risk, implement explicit consent mechanisms, robust access controls, secret management, and auditing for enrichment endpoints and data stores. Consider adding formal data governance ADRs, minimal data collection by default, and encryption/configuration details for the local vault and downstream indexing systems.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 08:28 PM
Package URL
pkg:socket/skills-sh/joelhooks%2Fjoelclaw%2Fcontacts%2F@f65e6ed1aed209a13b5af0b696e7c1168bc57021