email-send

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The file is a benign documentation snippet showing how to send email via SMTP using curl or Python. No obfuscated or overtly malicious code appears. Primary security concerns are operational: plaintext credentials in environment variables and especially passing credentials on the curl command line, and the high-impact nature of enabling outbound email (which can be abused for phishing or data exfiltration if misused by an automated agent). Recommend operational mitigations: avoid command-line credentials, use least-privilege credentials, require explicit user consent for sending messages, and audit activity.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:14 AM
Package URL
pkg:socket/skills-sh/ThinkfleetAI%2Fthinkfleet-engine%2Femail-send%2F@cbde85b74f8e6b2aca7da0222bb67d89942da2c7