AgentPod is building a private, secure device for your AI agent.The AgentPod device is coming.Coming soonBe first
We checked this and rejected itprivacy

Claude Chief of Staff: why it is not safe to use

We found no hidden code or unsafe installer behavior, but this skill is designed to access sensitive messages and calendar data from connected accounts.

What we found

Our review did not find hidden instructions, hardcoded secrets, remote code fetching, obfuscated files, or destructive installer behavior in this repo. The prompts and setup files are readable, and the installer only creates local directories and copies template files.

The main concern is privacy scope. This skill is designed to work with user-connected MCP services including Gmail, Google Calendar, Slack, WhatsApp, and iMessage. In practice, that means it can read highly sensitive personal and workplace data from those connected accounts in order to perform its assistant functions. We did not find evidence of undisclosed third-party exfiltration in the repo, but the intended access level is broad enough that users should make a deliberate choice before enabling it.

What to do instead

Only connect the accounts this skill truly needs, and avoid linking personal or high-sensitivity communication channels unless that access is necessary. Review the MCP services you authorize, use the smallest available permissions, and prefer test or limited-scope accounts when evaluating the skill. If you need similar workflow help with less exposure, choose tools that do not require access to private messages or calendars.

Want the same outcome, safely? Use our checked skill instead.

Source: https://github.com/mimurchison/claude-chief-of-staff

We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.

Copied to clipboard. Paste it into your AI (ChatGPT, Claude, or your agent) to add the skill.