crm-sync

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The business purpose is coherent for a CRM sync skill, and the approval gate helps, but the actual execution path is under-specified: crm-sync.py and the 'CRM MCP' are not tied to any verifiable official package, repo, or vendor-documented connector. That unverifiable dependency and likely credential forwarding make the skill high risk despite otherwise plausible functionality.

Confidence: 81%Severity: 76%
Audit Metadata
Analyzed At
May 15, 2026, 09:41 AM
Package URL
pkg:socket/skills-sh/indranilbanerjee%2Fdigital-marketing-pro%2Fcrm-sync%2F@f67ca0e8968400222b137ac8b551ec0100deb125
Security Audit — socket — crm-sync