sales-deal-room

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core deal-room guidance is aligned with its sales purpose, and the Qwilr token is used against Qwilr's official API. However, the skill expands into webhook analytics that route buyer-engagement data to an arbitrary external endpoint, includes a self-modifying file-write pattern, and instructs transitive installation of another skill from an unverified repo/org. These issues are not fundamentally malicious, but they make the skill broader and riskier than a simple documentation/design skill.

Confidence: 88%Severity: 53%
Audit Metadata
Analyzed At
Apr 17, 2026, 06:09 PM
Package URL
pkg:socket/skills-sh/sales-skills%2Fsales%2Fsales-deal-room%2F@1f5b466bf5781dfc7679d5cae008d92b20a25725