investor-research

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align, and the GooseWorks install path appears same-org and documented. The main issue is data-flow integrity: credentials and all investor/contact queries are routed through GooseWorks proxy endpoints instead of direct vendor APIs, while the skill also reads the API key from a local credential file. That makes the skill higher-risk than a direct API integration, but not fundamentally incompatible with its stated purpose.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
May 5, 2026, 12:13 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Finvestor-research%2F@63a51e2d529ab770857c3bd0bf4f89e4a2038da9