mail

Warn

Audited by Socket on May 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The purpose and requested access are mostly coherent for a Mail-to-Reminders triage skill, and the visible data flow is local to macOS apps. The main issue is trust: key functionality is delegated to unverifiable local helper scripts and a custom `reminders-cli` with no provenance or release evidence, so the skill carries high supply-chain risk even without explicit malicious behavior or external exfiltration in the text.

Confidence: 83%Severity: 76%
Audit Metadata
Analyzed At
May 2, 2026, 03:35 PM
Package URL
pkg:socket/skills-sh/htlin222%2Fdotfiles%2Fmail%2F@fed9533742bfcae7cde6122b4e1a78f732c01cc1
Security Audit — socket — mail