follow-builders

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN in intent but HIGH-RISK in operation: the skill is largely purpose-aligned and uses official Telegram/Resend endpoints, with no obvious malware or deceptive installer. The main issues are autonomous outbound messaging/email, local plaintext secret storage, cron persistence, and opaque trust in a central feed service.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Apr 12, 2026, 05:58 AM
Package URL
pkg:socket/skills-sh/43COLLEGE%2F43-Agent-skills%2Ffollow-builders%2F@9b083fb4356e1f311b5c50a4720e8b9b2f3fd818