company-domain-lookup-logodev

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is narrow, but it reads a local Gooseworks credential file and routes all Logo.dev lookups through Gooseworks proxy endpoints rather than official Logo.dev APIs. That proxying and raw credential handling are disproportionate for a simple domain-search skill, though there is not enough evidence here to call it outright malicious.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:08 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fcompany-domain-lookup-logodev%2F@9675e08c34ae2e0d3ab702dd69885e81fe255ed4