cold_email

Fail

Audited by Socket on Feb 19, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The artifact is a benign templates-and-workflow document for cold email sequences, but it contains several high-risk operational recommendations that could enable abusive, deceptive, or non‑compliant outbound campaigns. Key dangerous items: explicit advice to omit unsubscribe handling, encouragement of opaque tracking and link shortening, and reliance on scraping/personal data without privacy controls. There is no technical malware present, but the supply-chain/privacy risk is material and actionable. Recommendations: remove or reword the advice to ignore unsubscribes and clearly require legal compliance (CAN-SPAM/GDPR); mandate explicit consent or lawful basis for scraping and personal-data use; require transparency for tracking links and disable covert tracking by default; add provenance checks for quoted case studies/name-drops; and add safeguards around volume/warm-up to prevent automated abuse. With those mitigations this skill can be used safely for legitimate sales outreach.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 19, 2026, 03:52 PM
Package URL
pkg:socket/skills-sh/manojbajaj95%2Fgtm-skills%2Fcold-email%2F@0970e4a7bb214f11af81a3ae0da3b9e8d739ede8