gorilladesk-private-api

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for GorillaDesk write automation and sends credentials only to same-vendor GorillaDesk endpoints, so this is not clear credential theft. But it relies on an undocumented private backend, uses powerful account credentials, and enables autonomous business-state changes and invoice creation through an AI workflow. The lack of third-party exfiltration keeps it below malicious, but the unsupported private API and high-impact write scope make the skill high risk.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Sep 4, 2026, 06:58 AM
Package URL
pkg:socket/skills-sh/delorenj%2Fskills%2Fgorilladesk-private-api%2F@443cd899712fca8d349c263ea0527c5a47b684d56815591b0bbc9a2a5f58f24a
Security Audit — socket — gorilladesk-private-api