social-inbox-agent
Warn
Audited by Socket on Apr 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is purpose-aligned and uses official-looking Late and Gemini endpoints with proportionate credentials, so it does not look like credential-harvesting malware. However, it enables autonomous outbound social messaging based on untrusted inbound content, which creates meaningful abuse and safety risk even without supply-chain or exfiltration red flags.
Confidence: 88%Severity: 74%
Audit Metadata