crm-sync

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated CRM-sync purpose is coherent, but the trust boundary is not: a required unverified local script and an unspecified MCP transport sensitive CRM data and likely auth context without clear provenance or endpoint transparency. No confirmed malware or overt exfiltration is shown, but the install/execution trust and data-flow integrity are too weak for a benign classification.

Confidence: 80%Severity: 72%
Audit Metadata
Analyzed At
Apr 1, 2026, 01:20 AM
Package URL
pkg:socket/skills-sh/indranilbanerjee%2Fdigital-marketing-pro%2Fcrm-sync%2F@b06b8cade0aa2ebfc66ca19009ef2dc08d4488b5