job-posting-intent

Fail

Audited by Socket on Apr 23, 2026

2 alerts found:

AnomalyMalware
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities broadly align, but it sends search activity and lead data through third-party services, including a non-official Apify marketplace actor and an intermediary Rube/Composio path for Google Sheets. This is not fundamentally incompatible with the stated lead-gen use case, but the preconfigured/default RUBE token note and indirect data flow make the trust model weaker than a direct official API integration.

Confidence: 85%Severity: 61%
MalwareHIGH
scripts/create_sheet_mcp.py

The code is not simply benign data processing. It builds and transmits a large remote-executable payload to a remote workbench, effectively enabling remote code execution on an external service. Coupled with a hardcoded JWT and dependence on external tooling (googlesheets via the remote workbench), this represents a high opportunity for misuse, data exposure, or control by an attacker if the remote service is compromised or abused. The immediate risk is remote code execution and data leakage via the remote workbench and Google Sheets API, amplified by hardcoded credentials.

Confidence: 65%Severity: 90%
Audit Metadata
Analyzed At
Apr 23, 2026, 01:07 PM
Package URL
pkg:socket/skills-sh/athina-ai%2Fgoose-skills%2Fjob-posting-intent%2F@12b7ab1ac9a99a6a2b0afe22387786702988896d
Security Audit — socket — job-posting-intent