portfolio-deal-linker
Warn
Audited by Socket on Mar 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s capabilities broadly fit its stated purpose, and its data flows appear aimed at legitimate sales attribution. Risk comes from trust gaps around unverified MCP server implementations, credential handling inside those servers, cross-system email/CRM correlation, and unnamed sibling-skill dependencies—not from overt malicious behavior or obvious exfiltration paths.
Confidence: 79%Severity: 58%
Audit Metadata