contact-finder-contactout

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, but its real data flow is through Gooseworks/Orthogonal rather than ContactOut's official API. Same-org install guidance lowers supply-chain concern, yet raw credential-file access plus third-party proxying of API keys and personal data makes the overall risk medium-high.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:08 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fcontact-finder-contactout%2F@20ba3d66be1a198773ec47a0b23e979e2cda0a2f