revenue-audit
Warn
Audited by Socket on May 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core capability is consistent with a revenue-audit skill, and requested ESP data broadly matches the stated purpose. The main concerns are overbroad permissions (`Bash`/`Read`/`Write`/`WebFetch`), dependence on a third-party Cogny MCP layer, and incomplete install provenance for `cogny-mcp`; these elevate security risk but do not indicate confirmed malware or clear credential theft.
Confidence: 84%Severity: 60%
Audit Metadata