find-leads

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with lead generation, but it combines raw secret reading, arbitrary web content ingestion, and autonomous CRM writes. The CRM endpoint appears same-org and there is no external installer or unverifiable binary, so this is not malicious or high supply-chain risk; the main concerns are credential handling, indirect prompt injection from fetched websites, and autonomous business actions.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 21, 2026, 12:35 AM
Package URL
pkg:socket/skills-sh/psquared-development%2Fpsquared-skills%2Ffind-leads%2F@94a6371b9a38784163e3192a84240c7a35f2da48
Security Audit — socket — find-leads