add-integration

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose is coherent, but it materially increases risk by discovering arbitrary third-party MCP packages and executing them via npx while supplying service credentials through environment variables. Data flows are mostly aligned with the integration goal and use official npm/MCP patterns, so this is not confirmed malware, but the package-selection and credential-forwarding model creates medium-high supply-chain risk.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
May 15, 2026, 01:59 PM
Package URL
pkg:socket/skills-sh/indranilbanerjee%2Fdigital-marketing-pro%2Fadd-integration%2F@b7c29e2eac429763e811e31dca0041c45f6f22d9
Security Audit — socket — add-integration