morning-brief

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capability is coherent for a sales-brief skill, and there is no installer, hidden execution, or obvious credential theft pattern. Risk comes from broad access to sensitive business systems, automated draft generation, optional auto-email/publication, and the unverified MCP wrapper layer that actually handles credentials and API calls.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Sep 17, 2026, 09:57 AM
Package URL
pkg:socket/skills-sh/scientiacapital%2Fskills%2Fmorning-brief%2F@57b32cfd1736ea661eacba46fff10fc4933cebe1939841699350ed90f99258a3
Security Audit — socket — morning-brief