learn

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and file access are mostly coherent for a marketing knowledge-base workflow, and there is no direct evidence of credential theft or off-platform exfiltration. However, it requires an unverifiable local executable (intelligence-graph.py), which triggers a high security-risk floor, and the broader project evidence shows same-org but still risky download-execute install patterns. Overall this looks more like a high-risk, unverifiable internal automation dependency than confirmed malware.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 1, 2026, 01:22 AM
Package URL
pkg:socket/skills-sh/indranilbanerjee%2Fdigital-marketing-pro%2Flearn%2F@b8dbe9b6d4e4b2ddb29890409f53227c5ca18abf