full-engagement-pipeline

Warn

Audited by Socket on Jul 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The accounting purpose largely matches the file access and local processing, but the skill includes an unspecified external `npx` extractor for highly sensitive financial documents. Because that external package is unnamed and unverifiable from the skill text, install trust and data-flow integrity are not adequate for the sensitivity of the task.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Jul 29, 2026, 10:04 AM
Package URL
pkg:socket/skills-sh/cynco-labs%2Fai-accounting-skills%2Ffull-engagement-pipeline%2F@26a97b1dc885d38c30cff47cb3ba10a63cc598fcd273c0cf134e5d842b50386f
Security Audit — socket — full-engagement-pipeline