churn-prevention
Audited by Socket on Feb 27, 2026
1 alert found:
AnomalyThis is a documentation/skill file describing churn-prevention strategies and tooling integrations. It does not contain executable code, obfuscated payloads, or explicit malicious instructions. The primary security concerns are operational: the skill encourages reading a local context file and using third-party CLIs and APIs (Customer.io, Stripe, PostHog, etc.), which requires credential handling. If an agent or user blindly executes CLI commands or forwards credentials to third-party tools without verification, there is a credible credential-forwarding and autonomy risk. There are no download-execute chains, hardcoded secrets, or network endpoints under attacker control present in the content. Overall the content is functionally appropriate for its purpose but would become high-risk if combined with autonomous command execution or careless credential handling.