goose-migrate

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's stated purpose and read/write scope are mostly coherent, and its GitHub access uses the official `gh` CLI. However, its key write path depends on an unverifiable `gw todo` binary with no confirmed official source or release trail, so the user is asked to trust a black-box intermediary for Todoist operations. That makes the overall footprint higher risk than the benign purpose suggests.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Mar 28, 2026, 02:21 AM
Package URL
pkg:socket/skills-sh/autumnsgrove%2Fgroveengine%2Fgoose-migrate%2F@6ac72ee08edaa6af73b1e08527a038bc63d27476