deepline-ads-audiences
Warn
Audited by Socket on Sep 6, 2026
1 alert found:
AnomalyAnomalyplays/enrich-audience-waterfall.play.ts
LOWAnomalyLOW
plays/enrich-audience-waterfall.play.ts
No clear malicious payload is evident in the provided fragment (no obfuscation/dynamic execution or direct credential/process manipulation). However, the module performs significant privacy-relevant behavior: it batches LinkedIn profile URLs and sends them to an external ContactOut-like tool to obtain hashed email identifiers, then returns LinkedIn URLs and aggregated personal hash pools to the caller. This makes the main security concern data governance, consent/legal compliance, and strict access control/log retention around both the external tool invocation and the returned enrichment payload.
Confidence: 60%Severity: 55%
Audit Metadata