email-campaign

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is plausible, but its actual data flow is a third-party proxy pattern. It reads a local credential file and sends prospect PII and API actions through Gooseworks rather than official provider endpoints, creating significant confidentiality and credential-handling risk even though the install path appears same-org.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:07 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Femail-campaign%2F@7aa3cef6c600c7a67b6fc988079dc4ab4bdaab66