linkedin-ads-bidding

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core guidance is benign marketing advice, but the skill’s footprint is broader than its stated LinkedIn bidding purpose because it pushes optional installation of external ColdIQ MCP tooling and credential use. Data flows stay within same-brand ColdIQ endpoints, so this is not clearly malicious, but the unpinned `npx` execution and third-party credential forwarding make it medium risk.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Jul 22, 2026, 06:40 PM
Package URL
pkg:socket/skills-sh/Cold-IQ%2FColdIQ-s-GTM-Skills%2Flinkedin-ads-bidding%2F@4ad57c06b6ffd60b6fa009f127412a848d3a46c8c1b0f32fbe56079675a88ea4
Security Audit — socket — linkedin-ads-bidding