contact-to-email

Warn

Audited by Socket on Mar 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s stated purpose (email discovery and verification from various starting points) is broadly aligned with its described workflows and external service integrations. However, the install flow (curl | bash installation from an unverifiable external URL) and the multiple outbound data flows to external services without verifiable security controls introduce significant supply-chain and data-exfiltration risks. The presence of an unverifiable binary installation path combined with credential/data transmission to third-party enrichment/validation services warrants a Suspicious to High risk assessment. Security risk is elevated due to unverifiable binary installation and broad external data flows; malware likelihood cannot be ruled out without source/binary provenance verification. Recommend avoiding curl | bash install paths, pinning/download-signing checksums, and ensuring all external service communications are properly authenticated, encrypted, and auditable before use.

Confidence: 98%Severity: 80%
Audit Metadata
Analyzed At
Mar 12, 2026, 04:37 AM
Package URL
pkg:socket/skills-sh/getaero-io%2Fgtm-eng-skills%2Fcontact-to-email%2F@7502b98f8cac1d2fe3c35ff978c9c2fe6f0b01ac