pp-gorgias

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and Gorgias capabilities are broadly aligned, and auth/data flow to official Gorgias endpoints looks legitimate. Risk is elevated because it requires an external same-org CLI that will receive API credentials, uses unpinned install paths, supports optional webhook egress, and adds an MCP trust chain with incomplete in-skill provenance details.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Jul 20, 2026, 11:01 PM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fprinting-press-library%2Fpp-gorgias%2F@6ff17b1fc2636206851da0fe041f97aa8316b99212d19c5313a0e37714c4b411
Security Audit — socket — pp-gorgias