brand-intel-branddev

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its data flow is weaker than expected because Brand.dev requests and bearer credentials are routed through a Gooseworks/Orthogonal proxy instead of the official Brand.dev API. This looks more like a managed gateway than overt malware, but the proxying and raw credential-file handling create meaningful trust and exposure risk.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:07 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fbrand-intel-branddev%2F@2cf10f9433d8b1390bf48e80d34e4c12aafab5dc