cold-email
Audited by Socket on Aug 17, 2026
5 alerts found:
Anomalyx4SecuritySUSPICIOUS. The skill’s stated purpose and API usage are coherent, and the ColdIQ endpoint appears same-org, but it instructs the agent/user to run an unpinned external npm MCP package and pass an API key into it without verified publisher provenance in the provided evidence. This is a moderate supply-chain and credential-forwarding risk, not confirmed malware.
SUSPICIOUS: The core writing purpose is legitimate, but the skill expands into third-party prospect enrichment and verification, encourages installing a mutable external MCP package, and forwards API-backed research through ColdIQ infrastructure. This is not confirmed malware, but its footprint is broader and riskier than a simple email-writing skill.
SUSPICIOUS: the skill’s core purpose is coherent, and its official web/API domains align with ColdIQ, but it extends a writing workflow into installation of an external MCP via unpinned `npx @latest` and forwards an API key to that code. This is more a trust/supply-chain concern than confirmed malicious behavior.
SUSPICIOUS: the copywriting purpose is mostly coherent, but the skill’s footprint extends into third-party lead enrichment and email verification, and it recommends executing an unpinned MCP package whose official provenance was not verified. The official ColdIQ domains reduce concern, but the combination of external package execution, API-key forwarding, and brokered data routing makes this higher risk than a normal documentation skill.
SUSPICIOUS. The skill's messaging purpose is coherent, and the network destination aligns with the stated ColdIQ service, but it expands from writing assistance into prospect enrichment and asks users to run an unpinned `npx` MCP package while forwarding an API key to that runtime code. This is a medium supply-chain and credential-forwarding risk, not confirmed malware.