gorgias
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose and commands are mostly coherent, and the CLI appears to be an official same-org npm package, so this is not strong evidence of malware. However, all Gorgias access and OAuth custody are routed through ClawLink's third-party hosted layer rather than direct official Gorgias API use, which creates meaningful credential-forwarding and data-flow risk for an AI agent integration.
Confidence: 86%Severity: 62%
Audit Metadata