lead-sources-guide
Warn
Audited by Socket on Jul 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose is coherent, but it couples a documentation-style guide to execution of an unpinned external MCP package and forwards an API key into that package. ColdIQ branding and endpoints look same-org, which lowers maliciousness, but the unverifiable package provenance keeps overall risk high.
Confidence: 83%Severity: 82%
Audit Metadata