gorilladesk-private-api
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent for GorillaDesk write automation and sends credentials only to same-vendor GorillaDesk endpoints, so this is not clear credential theft. But it relies on an undocumented private backend, uses powerful account credentials, and enables autonomous business-state changes and invoice creation through an AI workflow. The lack of third-party exfiltration keeps it below malicious, but the unsupported private API and high-impact write scope make the skill high risk.
Confidence: 86%Severity: 74%
Audit Metadata