configure-notifications

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core purpose is coherent for native Discord/Telegram/Slack config, but the skill’s footprint expands materially with arbitrary custom webhook and CLI gateways. The biggest concerns are persisted arbitrary command execution, forwarding session data through third-party local CLIs/services, and storage of notification secrets in a local config file. Not confirmed malware, but broader and riskier than a narrowly scoped notification setup.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Apr 16, 2026, 10:53 AM
Package URL
pkg:socket/skills-sh/Yeachan-Heo%2Foh-my-codex%2Fconfigure-notifications%2F@b0259e087f6ceb90fe36386972630b439641fc2d