newsletter-campaign-workflow

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This file is a workflow and developer documentation/skill manifest for newsletter campaign processing. It describes expected DB filters, cron jobs, AI integration, and step-by-step workflows. I found no evidence of malicious code, obfuscated payloads, download-and-execute commands, or explicit credential harvesting patterns in the provided text. The primary security concerns are operational: ensuring the runtime implementations of callAIWithPrompt and the Supabase admin client do not leak credentials, that all DB queries properly include publication_id to prevent cross-tenant data leakage, and that logs do not expose sensitive data. No direct supply-chain or exfiltration indicators are present in this document itself.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 04:52 AM
Package URL
pkg:socket/skills-sh/venture-formations%2Faiprodaily%2Fnewsletter-campaign-workflow%2F@c5aba16eca8e9123e2bda6ccec7cf5c91872cc1c