comprehensive-enrichment

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s enrichment purpose broadly matches its capabilities, but it reads raw credentials from a local file and sends all sensitive lookup data through Gooseworks’ proxy rather than directly to the named providers. Same-org Gooseworks branding reduces the chance of outright malware, yet the proxy data flow, aggressive personal-data collection, and incompletely verified unpinned `npx` install make the overall skill medium-high risk.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:07 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fcomprehensive-enrichment%2F@f66d010b6fc9cde8ccf8277aa84d7e5e00678a44