linkedin-repurposing

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core purpose and content are benign and aligned with LinkedIn repurposing, but it also nudges installation of an external MCP package and forwards an API key to it. Because the install is unpinned and the exact npm package provenance was not independently verified in the provided evidence, the trust model is weaker than a pure documentation skill, though there is no strong sign of malicious intent or off-purpose data exfiltration.

Confidence: 82%Severity: 52%
Audit Metadata
Analyzed At
Jul 22, 2026, 06:39 PM
Package URL
pkg:socket/skills-sh/Cold-IQ%2FColdIQ-s-GTM-Skills%2Flinkedin-repurposing%2F@646a24919c636d94e31b723a67dbd14da467a09d0cba4ca65c4e9afad98967f9
Security Audit — socket — linkedin-repurposing