lead-writer

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core writing purpose is benign, but the skill’s actual footprint includes opaque local executables, background analytics, config inspection, and workspace mutation that are broader than necessary for copy generation. No confirmed malware or explicit attacker endpoint is shown, but the unverifiable helper binaries create a high trust and security risk.

Confidence: 81%Severity: 82%
Audit Metadata
Analyzed At
Aug 11, 2026, 01:40 PM
Package URL
pkg:socket/skills-sh/coleschaffer%2Fdtc-copywriting-skills%2Flead-writer%2F@a409d28bca8e3930c6fab6f186f25739cf69e3100387979af4f228b2102bff36
Security Audit — socket — lead-writer