sendfox

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and required SendFox token are broadly coherent, and no clear exfiltration endpoint is shown, but the install path depends on an unverifiable custom CLI built via local scripts with no official SendFox distribution evidence. Main risk is supply-chain and credential forwarding through opaque tooling, not confirmed malware.

Confidence: 83%Severity: 81%
Audit Metadata
Analyzed At
Apr 1, 2026, 01:05 PM
Package URL
pkg:socket/skills-sh/cathrynlavery%2Fsendfox-skill%2Fsendfox%2F@3dedd8795f84c183db0675eb28474ad35736e803
Security Audit — socket — sendfox