job-search

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's job-search purpose broadly matches its capabilities, and the credential location/install model appears consistent with official Gooseworks documentation. The main concern is data-flow integrity: all requests and the bearer token are routed through Gooseworks proxy endpoints instead of direct provider APIs, and the skill reads raw credentials from a local file. This looks more like a managed gateway pattern than confirmed malware, but it introduces meaningful credential-handling and privacy risk.

Confidence: 89%Severity: 66%
Audit Metadata
Analyzed At
May 5, 2026, 12:13 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fjob-search%2F@ffae606b7031b1c242d5ef0e8c1837a58626b988