copywriting

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the copywriting purpose is mostly coherent, but the skill’s footprint extends into third-party lead enrichment and email verification, and it recommends executing an unpinned MCP package whose official provenance was not verified. The official ColdIQ domains reduce concern, but the combination of external package execution, API-key forwarding, and brokered data routing makes this higher risk than a normal documentation skill.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
Jul 22, 2026, 06:39 PM
Package URL
pkg:socket/skills-sh/Cold-IQ%2FColdIQ-s-GTM-Skills%2Fcopywriting%2F@f0dcb90e37e507ced7e75ba61d36df931e0cec78a384c8af8e7289b7174aadd8
Security Audit — socket — copywriting