luma-event-attendees

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core behavior matches its stated purpose, and install instructions use official channels, but the paid feature depends on a third-party community Apify actor and forwards an API token to that external service. That makes the trust boundary broader than a simple scraper and creates medium security risk, though there is no clear evidence of hidden exfiltration or outright malware.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 10, 2026, 10:48 AM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fluma-event-attendees%2F@a4c4082c18b855f8da3019dbfe594bed910505d2