cohort-analysis

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Functional cohort analysis workflow with reasonable purposes (cohort segmentation, retention matrices, LTV calculation, recommendations). No direct indicators of embedded malware or obfuscated/malicious code in the provided fragment. Primary risks are supply-chain and operational: unspecified agent behaviors, unclear credential handling, unvetted persistence script (churn-predictor.py), and broad data access scope that includes PII and transaction history. Recommendations: require documented, direct-to-official-API auth flows (OAuth with limited scopes or short-lived tokens), avoid giving agents persistent credentials, provide/vet churn-predictor.py or include its logic inline, minimize requested fields (principle of least privilege), encrypt sensitive config and outputs, and enforce logging/audit of data access and retention policies.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 27, 2026, 01:03 PM
Package URL
pkg:socket/skills-sh/indranilbanerjee%2Fdigital-marketing-pro%2Fcohort-analysis%2F@c83a407b2e67fa9af400fa42e7f7a46ba526bb0a