goose

Warn

Audited by Socket on Jul 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is broadly aligned with its purpose as a Goose guide, but it enables a high-impact agent footprint and includes credential forwarding to external MCP server code via unpinned `npx` installs. No direct malware, hidden execution, or explicit exfiltration is shown, but the combination of broad system agency, third-party extension execution, and secret passing makes it medium/high risk.

Confidence: 83%Severity: 71%
Audit Metadata
Analyzed At
Jul 19, 2026, 07:13 AM
Package URL
pkg:socket/skills-sh/TerminalSkills%2Fskills%2Fgoose%2F@5c4cc6b59e7e98d0e5f6ffecabbceb9b1707e898ebb31b6b71aea71f28879a3a
Security Audit — socket — goose