gorgias

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and commands are mostly coherent, and the CLI appears to be an official same-org npm package, so this is not strong evidence of malware. However, all Gorgias access and OAuth custody are routed through ClawLink's third-party hosted layer rather than direct official Gorgias API use, which creates meaningful credential-forwarding and data-flow risk for an AI agent integration.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fgorgias%2F@fca43dbea2cacba5f3dad84513e214da870a79c1e46ea6c394d3e6120c380e5f
Security Audit — socket — gorgias