gtm-enrichment-deep

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s enrichment purpose is plausible, but its actual data flow routes user PII and bearer-authenticated requests through a Gooseworks proxy instead of directly to the named providers, and it reads a raw local credential file. This is not confirmed malware, but the proxy-mediated architecture and limited public verification make the trust model weaker than the description suggests.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
May 5, 2026, 12:12 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fgtm-enrichment-deep%2F@33599708b05b5eff633358cadde77a13d4d0ac6f