demo-builder

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's sales-demo purpose is plausible, but its actual footprint is open-ended: it can research untrusted sites, execute Bash, and use credentials with arbitrary user-supplied APIs/SDKs/CLIs without built-in provenance or endpoint verification. There is no direct exfiltration endpoint or embedded malware, but the combination of credential forwarding, external-content ingestion, and execution makes it medium-to-high risk.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Apr 4, 2026, 06:52 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fdemo-builder%2F@35dbf510c9e7b910a406906e513a1569f1d49092