Goose Extensible AI Coding Agent by Block

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely coherent with its stated purpose as a coding agent guide, and the referenced Goose project appears to be an official Block offering with a verifiable release trail. The main risks are proportional but substantial: transitive skill installation, broad autonomous command/file capabilities, and prompt-injection exposure through web/MCP inputs. Not malware, but a medium-high risk agent-enablement skill.

Confidence: 89%Severity: 66%
Audit Metadata
Analyzed At
Mar 29, 2026, 02:34 AM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fgoose-extensible-ai-coding-agent-by-block%2F@b2d887eeca65728171daee1c375a2557b8ab33c0