aeo-audit

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, but its trust model is not. It relies on an `npx`-executed external CLI whose publisher relationship could not be verified, and it appears to forward an OpenAI API key to that tool. The website-scraping behavior matches the stated audit purpose, but the unverified package provenance makes the install and credential flow disproportionate.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Mar 26, 2026, 10:03 AM
Package URL
pkg:socket/skills-sh/athina-ai%2Fgoose-skills%2Faeo-audit%2F@505edd81471739ec1b9e552aaa8ac343d21fab0a