outreach-4-categories
Warn
Audited by Socket on Jul 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is mostly benign sales-taxonomy guidance, but it embeds a high-risk execution path by telling the agent/user to run an unpinned `npx` installer and pass an API key into a package whose npm provenance was not verified from the evidence. Same-org API usage is coherent with the purpose, but the install/credential-forwarding footprint is disproportionate for a taxonomy skill and triggers the unverifiable-binary-with-credentials risk floor.
Confidence: 89%Severity: 86%
Audit Metadata