sales-peerlist

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core Peerlist guidance is benign and proportionate, but the skill embeds a third-party transitive install command unrelated to Peerlist’s direct function. Risk comes from unpinned npm execution and trust inheritance into another skill, not from credential theft or overtly malicious behavior in this skill itself.

Confidence: 90%Severity: 52%
Audit Metadata
Analyzed At
Apr 9, 2026, 10:15 AM
Package URL
pkg:socket/skills-sh/sales-skills%2Fsales%2Fsales-peerlist%2F@8252a8399bcdbdb854cd4ce6322d35db55941e29