pipedrive

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Pipedrive functionality is coherent, and there is no malware-like installer or hidden execution. The main concern is data-flow integrity: all API traffic and bearer auth are routed through Maton's proxy instead of directly to Pipedrive, plus the skill references another third-party-published skill, increasing trust-chain risk.

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Sep 4, 2026, 01:52 PM
Package URL
pkg:socket/skills-sh/craftos-dev%2Fcraftbot%2Fpipedrive%2F@592d5ee45cbcf1a70b295767f9b93c5ff374a7e5224982930ce2e2c513b11fa6
Security Audit — socket — pipedrive