candidate-sourcing

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities mostly match its recruiting purpose, but it materially expands privacy and trust risk by harvesting personal emails from GitHub commit history, aggregating candidate PII into local trackers, and relying on MCP layers whose trust boundaries are only partly documented. Not confirmed malware, but medium security risk due to contact-data enrichment, third-party credential use, and semi-autonomous outreach preparation.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Aug 27, 2026, 01:00 PM
Package URL
pkg:socket/skills-sh/crustdata%2Fskills%2Fcandidate-sourcing%2F@c916b55426f3bf7ae786520a3f04444a94518c881431a66c62a5c0b4f1f2eb06
Security Audit — socket — candidate-sourcing