deal-intelligence

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly aligned with deal intelligence, but its footprint is expansive: it reads multiple communications sources, persists external content locally, sends company data to Extruct, and instructs autonomous CRM record creation. This looks more like a high-risk business automation skill than malware; the main concerns are over-broad data handling, prompt-injection exposure, and unintended writes rather than deceptive install behavior or credential theft.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Apr 17, 2026, 06:21 AM
Package URL
pkg:socket/skills-sh/extruct-ai%2Fgtm-cowork-skills%2Fdeal-intelligence%2F@6e45f8e53d35e67e8d38ba3e41f5440792a5c94a