competitor-post-engagers

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities mostly align, and Apollo usage is official and proportionate, but the core scraping step relies on an unofficial third-party Apify community actor that receives token-authorized work with no pinning or verification. This is a meaningful supply-chain and credential-forwarding risk, not clear malware.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Mar 14, 2026, 06:03 PM
Package URL
pkg:socket/skills-sh/athina-ai%2Fgoose-skills%2Fcompetitor-post-engagers%2F@f2ef9e4ca20a6971fd87feb112af8e4566588be1