content-decay-scan

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

No direct evidence of malware or malicious intent in the provided design. Primary security concerns are supply-chain and credential-handling risks: (1) executing an unreviewed local script (creative-fatigue-predictor.py) and (2) use of high-sensitivity analytics credentials without stated least-privilege controls or provenance for network endpoints. Functionality and requested accesses are proportionate to the tool's purpose, but the implementation must adopt strict safeguards (explicit user consent, script signing/inspection, minimal OAuth scopes, TLS/endpoint verification, and restrict outbound network I/O) to reduce the realistic risk of data leakage or unauthorized exfiltration. If those mitigations are applied, security risk is moderate-to-low; absent them, the supply-chain risk is elevated.

Confidence: 75%Severity: 55%
Audit Metadata
Analyzed At
Feb 27, 2026, 01:05 PM
Package URL
pkg:socket/skills-sh/indranilbanerjee%2Fdigital-marketing-pro%2Fcontent-decay-scan%2F@df4a596cc770693f8811fbd2a5f9c03a30d257d8