gong

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose matches its capabilities, but its core model routes Gong authentication and data/actions through ClawLink rather than direct Gong APIs. The npm install path is relatively standard, yet the third-party CLI plus hosted token custody and mediated actions create a medium-to-high security risk disproportionate to a simple Gong integration.

Confidence: 88%Severity: 69%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:44 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fgong%2F@bc84aaa8e3fa45ba56a9481fabcaae02d43471bda2b26b66a22df4f4467d2b58
Security Audit — socket — gong