meta-onboarding

Warn

Audited by Socket on Jul 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly aligned with legitimate Meta API onboarding and uses official Meta/Anthropic/PyPI sources, but it unnecessarily asks the user to disclose sensitive Meta secrets to the agent and then stores them locally. No clear malicious exfiltration is shown, yet the secret-handling pattern and execution of an unseen local script make this higher than benign.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Jul 27, 2026, 09:10 AM
Package URL
pkg:socket/skills-sh/swan-gtm%2Fgtm-skills%2Fmeta-onboarding%2F@48d079d28929762d9e29fc6a2433f0b3a1727d7a49f34fe0373dc1ab22cf180b
Security Audit — socket — meta-onboarding