goose

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The install path is relatively normal, but the skill is internally inconsistent about what 'Goose' is and routes authentication and API traffic through Membrane as a third-party intermediary instead of clearly documented official Goose endpoints. That mismatch and proxy-based data flow make the skill higher risk than a normal direct API integration.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgoose%2F@9a77a3a2c98cf38cc763152cd924adbd50efec4f