clay-to-deepline

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s migration purpose is plausible and mostly aligned, but its real footprint is high-risk because it instructs users to extract a live Clay session cookie, use it in scripted API calls, and route commands/data through Deepline where telemetry can capture payloads. The same-org curl|bash installer is a supply-chain hygiene issue, while the bigger concern is credential and data handling breadth.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Mar 13, 2026, 06:40 PM
Package URL
pkg:socket/skills-sh/getaero-io%2Fgtm-eng-skills%2Fclay-to-deepline%2F@5dfdbdad9ff1053db465cd6aec36835697531552