get-brand-assets

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose is coherent, but its data flow is not direct. It reads a raw local API key and sends requests through a Gooseworks proxy rather than the official downstream API path, and it includes an unverified `npx` login/install step. This looks more like a managed gateway integration than malware, but the proxy routing and configurable `api_base` create meaningful credential and data-flow risk.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
May 5, 2026, 12:13 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fget-brand-assets%2F@ae670e6a18b2a40cc01e67d82b1613030426f34f