sales-kit

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: Most of the skill is benign documentation for Kit/ConvertKit and uses official Kit endpoints, with no direct credential access or exfiltration. The main issue is the unrelated transitive skill installation note using an unpinned `npx` flow to fetch another skill from an unverified third-party repo, which expands trust beyond the skill’s stated purpose and raises medium supply-chain risk.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Apr 4, 2026, 09:43 AM
Package URL
pkg:socket/skills-sh/sales-skills%2Fsales%2Fsales-kit%2F@b324bf408bef70ee116236759e203e72a42f99bc