ai-marketing-claude-code-skills
Warn
Audited by Socket on May 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s broad purpose is coherent, but the trust model is weak. It installs a collection of downstream skills via scripts from a personal GitHub repo while branding points to a different publisher, and it encourages transitive skill loading plus API-key use. No confirmed credential theft or malicious exfiltration is shown in this excerpt, but the install provenance and trust expansion justify medium risk.
Confidence: 81%Severity: 69%
Audit Metadata