process-email-bookmarks

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

No explicit malicious code or obfuscation found in the provided skill description — the behavior matches the declared purpose. However, the workflow includes multiple risky operations (fetching arbitrary URLs and writing their content into local files, and automated mailbox state changes) and contains a hard-coded email account/label that leaks specifics. These behaviors create a moderate security risk that should be mitigated through parameterization, explicit auth/scoping, confirmation prompts, input sanitization, domain whitelisting, and audit logging before use in production.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 04:22 PM
Package URL
pkg:socket/skills-sh/maroffo%2Fclaude-forge%2Fprocess-email-bookmarks%2F@a85a927a0fec42345a622e07b76d85f707e425ec