campaign-analytics
Warn
Audited by Socket on Apr 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The public evidence is broadly consistent with a legitimate analytics skill, and there is no visible credential harvesting or third-party API proxying, but the install model depends on transitive skill installation from a mutable GitHub repo and includes a same-repo raw GitHub curl|bash path with no visible pinning or signatures. Because the actual SKILL.md was not directly inspected, the final assessment should be treated as medium-confidence and centered on install-trust risk rather than confirmed malicious behavior.
Confidence: 76%Severity: 61%
Audit Metadata