re-engagement

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, and its official web/API domains align with ColdIQ, but it extends a writing workflow into installation of an external MCP via unpinned `npx @latest` and forwards an API key to that code. This is more a trust/supply-chain concern than confirmed malicious behavior.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
Jul 22, 2026, 06:39 PM
Package URL
pkg:socket/skills-sh/Cold-IQ%2FColdIQ-s-GTM-Skills%2Fre-engagement%2F@873a4a1c95d51ca38399e0d52bcc63a2717478162d2fb6a882ca3f674ce040b5
Security Audit — socket — re-engagement