hubspot-deal-pipeline-automation

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Security
SecurityMEDIUM
references/implementation-guide.md

The visible code appears intended for legitimate HubSpot quota polling and schema validation, with no clear malware or obfuscated payload. The principal security concern is an apparently unauthenticated CRM data proxy that accepts arbitrary identifiers and uses a privileged HubSpot token, potentially enabling unauthorized data access or upstream API abuse. Input validation, authorization, bounded caching, and review of the omitted shared function and CI script are required.

Confidence: 94%Severity: 72%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:46 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Ftons-of-skills-marketplace%2Fhubspot-deal-pipeline-automation%2F@e4137cce698ce85af8cb71bb50adc2a0972363b1307ff1c7c16d4179395da145
Security Audit — socket — hubspot-deal-pipeline-automation