cold-email-outreach

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with outbound email automation, but it handles sensitive lead data, uses a high-privilege Supabase service role, invokes another skill transitively, and can perform real-world email campaign actions. Data flows mostly match stated purpose and there is an explicit launch gate, so this is not confirmed malicious; however, the transitive skill dependency and unverified Smartlead MCP configuration keep risk at medium.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Mar 14, 2026, 06:03 PM
Package URL
pkg:socket/skills-sh/athina-ai%2Fgoose-skills%2Fcold-email-outreach%2F@907289af88f90241c0ff12050c4995249d67bc0a