letterly-exporter
Audited by Socket on Feb 23, 2026
1 alert found:
Security[Skill Scanner] [Documentation context] Installation of third-party script detected The fragment represents a coherent, purpose-aligned automation workflow: export data from Letterly via Playwright and store it in an Obsidian vault. The described approach uses standard tools and local file operations without embedding credentials or performing remote exfiltration. While the concept is sensible, ensure proper handling of the vault directory permissions and confirm that downloaded data is restricted to authorized users. Overall, the footprint is benign and proportionate to the stated goal. LLM verification: [LLM Escalated] The skill is benign and aligned with its described purpose of exporting Letterly data to an Obsidian vault via local browser automation. Key mitigations include handling file naming, validating downloads, securing the persistent session directory, and preventing accidental data exposure. Overall, a well-scoped local automation with manageable risks.