ravi-inbox

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s stated purpose and data flows are mostly coherent for inbox reading, and it does not show obvious third-party interception. However, it depends on a `ravi` CLI that could not be independently verified from official install/release evidence while handling highly sensitive SMS/email and likely auth tokens; that makes the trust model disproportionately risky for an AI skill.

Confidence: 80%Severity: 82%
Audit Metadata
Analyzed At
Apr 10, 2026, 09:23 PM
Package URL
pkg:socket/skills-sh/ravi-hq%2Fravi-skills%2Fravi-inbox%2F@3d2b6d208082f06aa60abfd2bddbb86c5515ce2e