apify-buying-signal-detection

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose and direct capabilities are mostly coherent for recurring lead-signal collection, and it uses official Apify endpoints and credentials in expected ways. However, its real footprint depends heavily on numerous third-party Apify Actors and external automation tooling, creating a large transitive trust and credential-forwarding surface that is broader than a simple CSV aggregation skill. No clear evidence of outright malware or credential theft is present, but the supply-chain and autonomous scheduling risks are material.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Aug 13, 2026, 04:15 PM
Package URL
pkg:socket/skills-sh/apify%2Fawesome-skills%2Fapify-buying-signal-detection%2F@c0fc5a3ba1305b8732ba63419bb5aa451c7ce5fe12de3c1bbe183c2aa47f746e
Security Audit — socket — apify-buying-signal-detection