gong
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s purpose matches its capabilities, but its core model routes Gong authentication and data/actions through ClawLink rather than direct Gong APIs. The npm install path is relatively standard, yet the third-party CLI plus hosted token custody and mediated actions create a medium-to-high security risk disproportionate to a simple Gong integration.
Confidence: 88%Severity: 69%
Audit Metadata