email-campaign
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is plausible, but its actual data flow is a third-party proxy pattern. It reads a local credential file and sends prospect PII and API actions through Gooseworks rather than official provider endpoints, creating significant confidentiality and credential-handling risk even though the install path appears same-org.
Confidence: 89%Severity: 78%
Audit Metadata