funding-signal-monitor

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core monitoring purpose is plausible, but the footprint is broader than necessary because it forwards an Apify token to external marketplace actors and chains into downstream outreach skills. No confirmed malware or overt exfiltration appears in this skill file, yet third-party credential use, unspecified local helper scripts, and transitive trust make the skill medium-to-high risk.

Confidence: 87%Severity: 69%
Audit Metadata
Analyzed At
Mar 29, 2026, 05:17 PM
Package URL
pkg:socket/skills-sh/nikiandr%2Fgoose-skills%2Ffunding-signal-monitor%2F@d5783213cbf995b77578e706e9b544cac2c8704e