adcp-signals

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The specification itself is not executable code and contains no explicit malicious routines, but it allows high-risk behaviors if implemented directly as written. Primary risks: outbound calls to caller-supplied agent_url endpoints (data exfiltration / credential harvesting), underspecified authentication/authorization for platform actions, and lack of secure webhook verification for async activation. Recommendations: require allowlisting/verified agent endpoints (or mutual TLS), mandate standardized OAuth/token flows and avoid forwarding raw credentials, enforce webhook signing and verification, require RBAC/explicit operator confirmation for activation operations with potential billing impact, log and encrypt activation keys with strict retention policies, and validate/normalize all user-provided URLs and account identifiers. With these mitigations, the protocol can be used safely for its intended ad-targeting orchestration purpose.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 27, 2026, 01:21 AM
Package URL
pkg:socket/skills-sh/adcontextprotocol%2Fadcp%2Fadcp-signals%2F@b36e269b6e0e3d3779dfe383d9a764cb0b88aa1a