signal-scanner

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely aligned with its lead-scanning purpose and uses official vendor platforms, but it expands trust to third-party Apify actors, handles a high-privilege Supabase service role key, and can make consequential database/status updates. No clear malware or deceptive exfiltration is shown, yet the credential scope and third-party data-processing path make it medium risk.

Confidence: 85%Severity: 61%
Audit Metadata
Analyzed At
Apr 10, 2026, 10:48 AM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fsignal-scanner%2F@1d4b788e32b0c91c358ee85eae1e5a4af6852115