intercom-crm

Fail

Audited by Socket on Mar 5, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill's functional purpose (Intercom CRM integration) is benign and typical. However, the installation and authentication recommendations introduce substantial supply-chain and credential-exposure risks: unverified remote install scripts (curl|bash), a transitive canifi-env installer, optional storage of plaintext passwords, and use of Playwright CDP to access browser sessions. These combined patterns justify treating the package as moderate-to-high operational risk until the installer sources and canifi-env implementation are audited and installers are delivered with verifiable signatures or checksums. Do not run the provided curl|bash commands on production machines without code review or sandboxing; prefer OAuth and secure secret storage mechanisms.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 5, 2026, 10:44 PM
Package URL
pkg:socket/skills-sh/manojbajaj95%2Fgtm-skills%2Fintercom-crm%2F@9d11ea5ef3cc21ffbb71ca8e218e22b96954593a