apify-buying-signal-detection
Warn
Audited by Socket on Aug 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's purpose and direct capabilities are mostly coherent for recurring lead-signal collection, and it uses official Apify endpoints and credentials in expected ways. However, its real footprint depends heavily on numerous third-party Apify Actors and external automation tooling, creating a large transitive trust and credential-forwarding surface that is broader than a simple CSV aggregation skill. No clear evidence of outright malware or credential theft is present, but the supply-chain and autonomous scheduling risks are material.
Confidence: 86%Severity: 76%
Audit Metadata