deepline-ads-audiences

Warn

Audited by Socket on Sep 6, 2026

1 alert found:

Anomaly
AnomalyLOW
plays/enrich-audience-waterfall.play.ts

No clear malicious payload is evident in the provided fragment (no obfuscation/dynamic execution or direct credential/process manipulation). However, the module performs significant privacy-relevant behavior: it batches LinkedIn profile URLs and sends them to an external ContactOut-like tool to obtain hashed email identifiers, then returns LinkedIn URLs and aggregated personal hash pools to the caller. This makes the main security concern data governance, consent/legal compliance, and strict access control/log retention around both the external tool invocation and the returned enrichment payload.

Confidence: 60%Severity: 55%
Audit Metadata
Analyzed At
Sep 6, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/getaero-io%2Fgtm-eng-skills%2Fdeepline-ads-audiences%2F@9e0e1ebd53a83b50de48655b6e4914949ff09c38dc102476f7337d2c75403ac0
Security Audit — socket — deepline-ads-audiences