company-contact-finder

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior matches lead generation, and there is no explicit malware pattern, installer, or credential theft instruction. However, the skill routes queries through an unverifiable Gooseworks MCP intermediary rather than directly to the official Crustdata/SixtyFour APIs, creating medium supply-chain and data-flow risk due to unclear provenance and credential forwarding.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Apr 23, 2026, 01:07 PM
Package URL
pkg:socket/skills-sh/athina-ai%2Fgoose-skills%2Fcompany-contact-finder%2F@7fc95250ab3aaa720a7ca10c1ec33e1a1124d156
Security Audit — socket — company-contact-finder