outreach-4-categories

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is mostly benign sales-taxonomy guidance, but it embeds a high-risk execution path by telling the agent/user to run an unpinned `npx` installer and pass an API key into a package whose npm provenance was not verified from the evidence. Same-org API usage is coherent with the purpose, but the install/credential-forwarding footprint is disproportionate for a taxonomy skill and triggers the unverifiable-binary-with-credentials risk floor.

Confidence: 89%Severity: 86%
Audit Metadata
Analyzed At
Jul 22, 2026, 06:39 PM
Package URL
pkg:socket/skills-sh/Cold-IQ%2FColdIQ-s-GTM-Skills%2Foutreach-4-categories%2F@161ee408a64b209d75bca3312a6d5a610c432441e8c62739ca3ca410ec50a616
Security Audit — socket — outreach-4-categories