community-signals

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s overall behavior is coherent with forum lead discovery, but Reddit collection relies on third-party Apify scraping rather than official APIs, and the skill likely forwards an Apify token plus query data to external actor infrastructure. This is not clearly malicious, yet the third-party credential/data flow and untrusted-content processing with write/exec-capable tools create medium risk.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Apr 7, 2026, 02:29 AM
Package URL
pkg:socket/skills-sh/athina-ai%2Fgoose-skills%2Fcommunity-signals%2F@e0c8d40f0b1a836557e960203bdb009de6f20ffd