identity-verification-didit

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose is Didit identity verification, but its actual implementation routes credentials and very sensitive KYC/AML data through Gooseworks proxy endpoints rather than Didit’s official API. The npm-based Gooseworks CLI path appears somewhat legitimate, so this is not confirmed malware, but the intermediary data flow and direct credential-file reading are disproportionate and risky for the claimed integration.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
May 5, 2026, 12:13 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fidentity-verification-didit%2F@b7bc4cf6fd09709caadeb10ab3c5e8dbfba56e85
Security Audit — socket — identity-verification-didit