campaign-analytics

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The public evidence is broadly consistent with a legitimate analytics skill, and there is no visible credential harvesting or third-party API proxying, but the install model depends on transitive skill installation from a mutable GitHub repo and includes a same-repo raw GitHub curl|bash path with no visible pinning or signatures. Because the actual SKILL.md was not directly inspected, the final assessment should be treated as medium-confidence and centered on install-trust risk rather than confirmed malicious behavior.

Confidence: 76%Severity: 61%
Audit Metadata
Analyzed At
Apr 12, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/alirezarezvani%2Fclaude-skills%2Fcampaign-analytics%2F@de96ad4787d28235a01a8088f7b8014dfaaf4c0e