extract-webpage-data

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s goal is plausible, but its implementation has meaningful trust and data-flow issues. It instructs the agent to read a raw local credential file and routes all requests and scraped content through a Gooseworks proxy rather than the official vendor APIs, creating unnecessary intermediary visibility and concentrated trust. Not confirmed malicious, but the proxy-based architecture and direct credential-file access raise medium-high security concerns.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:07 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fextract-webpage-data%2F@007acfa7f00a9c3f37ee64ff81516c3540b582a5
Security Audit — socket — extract-webpage-data