signal-scanner

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely aligned with its lead-scanning purpose and uses official vendor platforms, but it expands trust to third-party Apify actors, handles a high-privilege Supabase service role key, and can make consequential database/status updates. No clear malware or deceptive exfiltration is shown, yet the credential scope and third-party data-processing path make it medium risk.

Confidence: 85%Severity: 61%
Audit Metadata
Analyzed At
Mar 14, 2026, 06:04 PM
Package URL
pkg:socket/skills-sh/athina-ai%2Fgoose-skills%2Fsignal-scanner%2F@c438266e74b8470b5ca886000628833491a2017b