facebook-leads

Warn

Audited by Socket on Jun 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s lead-generation purpose mostly matches its capabilities, but it relies on exposing a live Facebook session through third-party Reduck automation rather than official Facebook APIs. The optional write actions are clearly disclosed and gated, yet the combination of cookie-based auth, intermediary data flows, and transitive trust in another skill/service makes the overall security risk medium-high.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
Jun 26, 2026, 08:38 AM
Package URL
pkg:socket/skills-sh/reduck-ai%2Fskills%2Ffacebook-leads%2F@b060a4ea54d33940a8d8bdd9513abe094ba35e3b91b6aee6d91b3ae954870753
Security Audit — socket — facebook-leads