kol-discovery

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent, but the main execution path depends on a community Apify actor and forwards a token to third-party code rather than using an official LinkedIn data source. No clear install/dependency trust story is provided for the local script. This looks like a plausible outreach skill with medium-to-high security risk, not confirmed malware.

Confidence: 85%Severity: 69%
Audit Metadata
Analyzed At
Apr 10, 2026, 10:48 AM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fkol-discovery%2F@460defa3f00da8cdc9b2394c549efc0a55017e97