ai-video-calls-tavus
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's purpose is plausible, but its actual footprint is not well aligned: it reads a local Gooseworks credential file and forwards requests through Gooseworks proxy endpoints instead of Tavus official APIs. That intermediary data flow, combined with direct credential-file access and only partially verifiable Gooseworks CLI/package provenance, creates medium-high security risk without enough evidence for confirmed malware.
Confidence: 88%Severity: 79%
Audit Metadata