luma-event-attendees

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core behavior matches its stated purpose, and install instructions use official channels, but the paid feature depends on a third-party community Apify actor and forwards an API token to that external service. That makes the trust boundary broader than a simple scraper and creates medium security risk, though there is no clear evidence of hidden exfiltration or outright malware.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Mar 14, 2026, 06:04 PM
Package URL
pkg:socket/skills-sh/athina-ai%2Fgoose-skills%2Fluma-event-attendees%2F@9fedb967852650926d25f61754e840c91fa8a25d