email-finder-tomba

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's functionality mostly matches lead-enrichment use cases, but it routes all requests through a Gooseworks proxy instead of Tomba's official API, reads a local credential file, and depends on an unverified `npx` login path. The main concern is third-party interception and install trust, not confirmed malware.

Confidence: 88%Severity: 78%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:08 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Femail-finder-tomba%2F@6bda389d1980d3b48c3a777e75d86dcb92f0c1c1