find-leads

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with lead generation, but it combines raw secret reading, arbitrary web content ingestion, and autonomous CRM writes. The CRM endpoint appears same-org and there is no external installer or unverifiable binary, so this is not malicious or high supply-chain risk; the main concerns are credential handling, indirect prompt injection from fetched websites, and autonomous business actions.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 21, 2026, 12:35 AM
Package URL
pkg:socket/skills-sh/psquared-development%2Fpsquared-skills%2Ffind-leads%2F@94a6371b9a38784163e3192a84240c7a35f2da48