inbound-lead-triage

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core lead-triage behavior is coherent, but the skill is loosely scoped and allows sensitive lead data to flow through optional third-party intermediaries and scraping tools instead of clearly requiring official APIs. No strong malware indicators or installer abuse are present, yet the PII handling and intermediary data-flow model create medium security risk.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 10, 2026, 10:50 AM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Finbound-lead-triage%2F@1cbd2ea702ea7551320842a0eb1ef0477e6f856c