api-tester

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is API testing, but the actual workflow routes all testing and documentation retrieval through Gooseworks proxy/search services, giving Gooseworks access to bearer credentials, target URLs, and scraped content. The capability is partly aligned with the purpose, but the data flow is not transparent or minimal, and the skill reads raw local credentials instead of using a safer auth flow. No confirmed malware or overt exfiltration endpoint is shown, but the proxy-mediated design and credential-file access make this a medium-high security risk.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:07 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fapi-tester%2F@6fd83603737b7863b02fd52f8ab32b23d8046301