pp-salesloft
Warn
Audited by Socket on Jul 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose and read-only Salesloft scope mostly align, and the install sources appear same-org and verifiable. However, the skill depends on external binaries, forwards bearer tokens into that CLI, supports arbitrary webhook delivery of CRM data, and includes MCP transitive installation; these make it higher-risk than a simple documentation or direct API skill, though not confirmed malicious.
Confidence: 86%Severity: 61%
Audit Metadata