investor-call-prep
Warn
Audited by Socket on May 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The overall purpose is plausible, but the implementation is over-centralized through Gooseworks proxy endpoints that receive calendar data, company details, and research queries instead of using official APIs directly. The direct credential-file read, credential forwarding to a gateway, and automatic Google Sheets export make the skill's data flow broader and riskier than its stated investor-prep purpose.
Confidence: 89%Severity: 83%
Audit Metadata