blog-inboxmate

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s publishing purpose is coherent, but it grants an agent high-impact autonomous authority to research untrusted web content, modify website files, and publicly push to main without confirmation. Main risk is autonomous public posting plus indirect prompt injection, not malware or credential theft.

Confidence: 93%Severity: 78%
Audit Metadata
Analyzed At
Apr 10, 2026, 07:38 AM
Package URL
pkg:socket/skills-sh/psquared-development%2Fpsquared-skills%2Fblog-inboxmate%2F@4c5e7a79352aab14a67fc156985c8c8833e09d3b
Security Audit — socket — blog-inboxmate