ai-video-calls-tavus

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose is plausible, but its actual footprint is not well aligned: it reads a local Gooseworks credential file and forwards requests through Gooseworks proxy endpoints instead of Tavus official APIs. That intermediary data flow, combined with direct credential-file access and only partially verifiable Gooseworks CLI/package provenance, creates medium-high security risk without enough evidence for confirmed malware.

Confidence: 88%Severity: 79%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:07 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fai-video-calls-tavus%2F@87784eae495f55251300c08c270dcd3700f66d20