sales-getresponse

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the main GetResponse support behavior is coherent and mostly benign, but the skill embeds an unpinned third-party transitive skill installation command unrelated to the publisher’s org. That trust-boundary jump raises medium supply-chain risk even though there is no direct credential theft or exfiltration in the provided content.

Confidence: 89%Severity: 53%
Audit Metadata
Analyzed At
Apr 17, 2026, 06:29 PM
Package URL
pkg:socket/skills-sh/sales-skills%2Fsales%2Fsales-getresponse%2F@de4a702e46c67e1686e74980dc51c2185a212f5c