sales-sally
What this skill does
Meeting transcription, note-taking, and AI integration via MCP server for sales and meeting intelligence
github/sales-skills - API Security - 89 stars
Threat analysis
Skill info
pkg:github/sales-skills/sales@01ed049?skill=sales-sallyAssessments (2)
API Security
API Security via local-llm-review
references/sally-api-reference.md
MCP connector exposes read-only access to meeting data via Bearer token authentication. Tokens are scoped to one user + one company account but can be used to access recordings the user owns, is the tAuthentication Best Practices
Authentication Best Practices via local-llm-review
references/sally-api-reference.md
The MCP connector uses Bearer tokens with no mention of refresh tokens or token rotation. This could increase the risk of token compromise over time.Badge
Add the Anomity scan badge for sales-sally to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of sales-sally? Report an issue or request a rescan.




