linkedin-storytelling

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the writing functionality is coherent, and ColdIQ domain/API usage matches the stated purpose, but the skill also instructs the agent/user to run an external MCP package with an API key via mutable npx @latest. Because the exact @coldiq/mcp package provenance was not verified, the main risk is supply-chain plus credential forwarding rather than clear malicious intent.

Confidence: 84%Severity: 67%
Audit Metadata
Analyzed At
Jul 22, 2026, 06:40 PM
Package URL
pkg:socket/skills-sh/Cold-IQ%2FColdIQ-s-GTM-Skills%2Flinkedin-storytelling%2F@d58e0d7527104909d781c11bfe30859b53c4ea61a308e36f435017c8abedb05a
Security Audit — socket — linkedin-storytelling