sales-proposal-analytics

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core analytics and Qwilr API usage are broadly aligned with the stated sales purpose and use official Qwilr endpoints, so there is no strong evidence of credential theft or malicious exfiltration. The main risk comes from the transitive `npx skills add` installation instruction to an unverified skill target, plus arbitrary webhook forwarding to user-chosen endpoints and minor persistent file writes. Overall this looks like a mostly legitimate sales skill with moderate trust-chain risk rather than malware.

Confidence: 87%Severity: 54%
Audit Metadata
Analyzed At
Apr 17, 2026, 06:10 PM
Package URL
pkg:socket/skills-sh/sales-skills%2Fsales%2Fsales-proposal-analytics%2F@ec81572ef9bbe9ad0c74667bf02d27cb6c4ca645