signal-sourcer

Warn

Audited by Socket on Aug 17, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
.claude/skills/website-visitors/SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are mostly coherent for website visitor tracking, and its stated API endpoint aligns with the vendor’s own domain. The main concern is install/execution trust: it asks the agent to auto-run an unpinned external MCP package whose exact provenance was not independently verified, while also passing an API key to that package. No direct malware, stealth, or clear exfiltration behavior is present in the skill text.

Confidence: 82%Severity: 78%
SecurityMEDIUM
.claude/skills/job-changes/SKILL.md

SUSPICIOUS: The business purpose and capabilities are mostly aligned, but the install path asks users to execute an unpinned external MCP package and pass it an API key without strong independently verified package provenance in the provided evidence. Data flows to ColdIQ are consistent with the stated purpose, so this is not clearly malicious, but supply-chain and credential-forwarding risk are material.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Aug 17, 2026, 06:00 AM
Package URL
pkg:socket/skills-sh/cold-iq%2Fcoldiq-s-gtm-skills%2Fsignal-sourcer%2F@ac024132ac029c549cdd2f8be0c0c0aa92d777e25189fe14ec7e5e33969d0d44
Security Audit — socket — signal-sourcer