portfolio-prospecting

Warn

Audited by Socket on Apr 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the shortcut itself is minimal and not overtly malicious, but it delegates control to a separate meta-skill and additional docs, creating a meaningful transitive-trust risk. The main concern is indirect execution of unreviewed downstream instructions rather than direct credential theft or malware behavior in this file.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 5, 2026, 09:52 PM
Package URL
pkg:socket/skills-sh/getaero-io%2Fgtm-eng-skills%2Fportfolio-prospecting%2F@34ecdb0df0d165099d52af89e6f4a0451c0aeb2c