email-processing

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s email-processing purpose is plausible, but the actual integration path appears to rely on third-party MCP infrastructure rather than official Google Gmail API endpoints. Combined with Bash access, broad file permissions, and possible credential/data forwarding through non-Google services, the footprint is not well-scoped for a Gmail skill.

Confidence: 85%Severity: 76%
Audit Metadata
Analyzed At
Apr 9, 2026, 10:43 PM
Package URL
pkg:socket/skills-sh/maneeshanif%2FAI-Employee-Hackathon-spec-driven%2Femail-processing%2F@5fe05f770f399864313da1b89f419f61beea1307
Security Audit — socket — email-processing