web-search-perplexity

Warn

Audited by Socket on May 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s functionality matches web search/chat, but its data flow does not match its branding: it reads a local Gooseworks credential file and sends prompts plus bearer-authenticated requests through Gooseworks proxy endpoints instead of Perplexity’s official API. This is not confirmed malware, but the intermediary routing and raw credential-file handling create meaningful trust and privacy risk.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
May 10, 2026, 06:08 PM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Fweb-search-perplexity%2F@d7c7c7b5cfa363a792a706ece92caf69f181af72