pp-gorgias
Warn
Audited by Socket on Jul 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose and Gorgias capabilities are broadly aligned, and auth/data flow to official Gorgias endpoints looks legitimate. Risk is elevated because it requires an external same-org CLI that will receive API credentials, uses unpinned install paths, supports optional webhook egress, and adds an MCP trust chain with incomplete in-skill provenance details.
Confidence: 87%Severity: 72%
Audit Metadata