agency-digest-setup

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The material presents a solid, purpose-aligned setup for a multi-brand Slack digest automation. It is not inherently malicious, but it requires proper secret management (encrypting or restricting access to brands.json and .env) and careful handling of logs to prevent credential leakage. Recommend enhancing guidance on secret storage, access permissions, and portability (consider non-macOS schedulers) while validating that templates do not ship with embedded secrets. Overall security outlook remains moderate with best-practice secret management and transparent scheduling controls.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:55 PM
Package URL
pkg:socket/skills-sh/victorpay1%2Fintelligems-plugins%2Fagency-digest-setup%2F@cb8fbe3114805645fc4c9a23bfd3a3bc12a26478
Security Audit — socket — agency-digest-setup