revenue-audit

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capability is consistent with a revenue-audit skill, and requested ESP data broadly matches the stated purpose. The main concerns are overbroad permissions (`Bash`/`Read`/`Write`/`WebFetch`), dependence on a third-party Cogny MCP layer, and incomplete install provenance for `cogny-mcp`; these elevate security risk but do not indicate confirmed malware or clear credential theft.

Confidence: 84%Severity: 60%
Audit Metadata
Analyzed At
May 2, 2026, 06:44 AM
Package URL
pkg:socket/skills-sh/cognyai%2Fclaude-code-marketing-skills%2Frevenue-audit%2F@17d7e3b5072928315bacf978b105428eca396b02
Security Audit — socket — revenue-audit