activecampaign
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's ActiveCampaign purpose is coherent, but its actual access model depends on a third-party intermediary that stores OAuth tokens and receives user data and action requests. The npm-based CLI appears same-brand and plausibly legitimate, so this is not confirmed malware, but the credential and data-routing footprint is broader than a direct official ActiveCampaign integration.
Confidence: 85%Severity: 66%
Audit Metadata