ops-inbox

Warn

Audited by Socket on Oct 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose matches inbox management, but its footprint is unusually broad: it reads full cross-channel communications, drafts and sends replies, archives content, and schedules recurring actions. The strongest risk is trust and credential forwarding through unverifiable local binaries/MCP helpers such as ops-discord and ops-unread; under the required scoring floors, that makes this high security risk even without confirmed malware.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Oct 8, 2026, 08:57 PM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fops-inbox%2F@c72c62f13d621acb0848285250525f8bf0e9b80731144da2b293eb8f3b92ce1f