gtm-tools

Warn

Audited by Socket on Jul 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is broadly aligned with a sales-automation API, but it carries meaningful risk: remote pipe-to-shell installation, autonomous API self-registration, browser-session-backed social actions, and financial top-up operations. Data flows appear to the claimed service domain rather than an obvious exfiltration host, so this is not confirmed malware, but the operational footprint is high-risk for an agent skill.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Jul 25, 2026, 02:35 PM
Package URL
pkg:socket/skills-sh/arnaudjnn%2Fgtm-skills%2Fgtm-tools%2F@e0a20513ccfdd8eb7286903f69a272653d9ba449564c402377428500ae3c8d9b
Security Audit — socket — gtm-tools