comment-funnel

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely purpose-aligned and uses same-org Upload-Post docs/API endpoints, with no installer or obvious malware signals. Risk is driven by third-party credential forwarding, unverified persistent monitor endpoints, and autonomous outbound DM actions on the user's behalf.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Mar 28, 2026, 10:42 PM
Package URL
pkg:socket/skills-sh/mutonby%2Fupload-post-comment-funnel%2Fcomment-funnel%2F@d566cffe0b9076e168f98d659be5c430005f440d