competitor-signals

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core capability matches the stated lead-generation purpose, and official Product Hunt API use is coherent. Main concerns are the optional Apify fallback, which can route token-backed scraping through community-maintained third-party actors, plus broad web-content ingestion with write/exec-capable tools and profiling of individuals for outreach. No direct malware, hidden exfiltration, or unverifiable binary install is evident.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 10, 2026, 10:49 AM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fcompetitor-signals%2F@a1ad57b0c7909ba64b20ed22ca29962dd6dfb68f