subject-lines

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose and API usage are coherent, and the ColdIQ endpoint appears same-org, but it instructs the agent/user to run an unpinned external npm MCP package and pass an API key into it without verified publisher provenance in the provided evidence. This is a moderate supply-chain and credential-forwarding risk, not confirmed malware.

Confidence: 80%Severity: 58%
Audit Metadata
Analyzed At
Jul 22, 2026, 06:39 PM
Package URL
pkg:socket/skills-sh/Cold-IQ%2FColdIQ-s-GTM-Skills%2Fsubject-lines%2F@d7ec8f4eb67d60eb4b4ef3deba8014788ae9484473920496dc1f44c0cc75d8da
Security Audit — socket — subject-lines