Deal Next Best Actions

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Functionally benign for its stated sales-assistant purpose, but operational risks exist because the skill ingests and echoes untrusted external content and implies CRM write actions without explicit authorization flows. Primary risks: indirect prompt injection via transcripts or web results, potential PII leakage in outputs, and unintended autonomous CRM writes if platform permissions are broad. No signs of embedded malware or obfuscated malicious code in the provided fragment. Recommend platform mitigations: read-only defaults, explicit user confirmation and audit for writes, PII redaction policies, and input sanitization/prompt-injection defenses before deploying.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 3, 2026, 11:40 AM
Package URL
pkg:socket/skills-sh/SixtySecondsApp%2Fuse60%2Fdeal-next-best-actions%2F@81615177154a402d9d0d069d5b0f3af75ad47d26