inbox
Audited by Socket on Mar 11, 2026
1 alert found:
Obfuscated FileThe Inbox skill is broadly coherent with its stated purpose of fetching and processing items from mobile via email, including newsletters and regular items. However, there are noteworthy security concerns: plaintext storage of mailbox credentials (config.json), potential exposure of email contents in queue storage, and external URL fetches without explicit security controls (allowlists, TLS checks, and logging safeguards). The data flow generally matches the described processes, but the design would benefit from stronger credential handling, clearer data minimization, and explicit security controls around external fetches. Overall, the skill is Benign-to-Suspicious: functional and purposeful but with identifiable security gaps that should be remediated to elevate to Benign.