data-charts-tako

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose is coherent, but its data flow is not: it reads a local Gooseworks credential file and sends that bearer token plus user data to a Gooseworks proxy instead of Tako's official API. This looks more like a managed gateway than direct integration, increasing credential-forwarding and interception risk even though the overall functionality matches the claimed chart/search use case.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:08 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fdata-charts-tako%2F@fc236bff33a8dda47960d780153ddce521a68f65