email-triage

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The stated purpose is coherent, but the skill relies on a separate unreviewed gmail-commander script/binary, forwards sensitive inbox-derived data to Telegram, and runs on a schedule with unattended external effects. The main concern is transitive trust and unverifiable local executable use rather than confirmed malicious intent.

Confidence: 79%Severity: 74%
Audit Metadata
Analyzed At
Apr 4, 2026, 09:55 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Femail-triage%2F@04ba1572bf9185466c4ff67409a640be9523755a