hubspot-security-queue

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/run-report.mjs

No direct evidence of intentional malware in this JavaScript orchestrator. The dominant security concern is supply-chain execution risk: it executes a Python script located under a CLI-provided directory and passes all environment variables (including secrets) to that subprocess. It also exfiltrates SKILL.md and generated report data to a third-party AI service and can post the resulting summary to a Slack webhook provided via environment variable. Net: medium-to-high security risk primarily due to execution of untrusted/local code paths and secret exposure to the child process; malware likelihood from this snippet alone appears low.

Confidence: 66%Severity: 70%
Audit Metadata
Analyzed At
Apr 15, 2026, 08:27 AM
Package URL
pkg:socket/skills-sh/WalletConnect%2Fskills%2Fhubspot-security-queue%2F@f7b4360629cb68266d55ded2c867f3b2cefca565
Security Audit — socket — hubspot-security-queue