fathom
Warn
Audited by Socket on Mar 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is plausible for a Fathom integration, but the core dependency is an unverifiable `fathom` CLI that receives API keys and can export or forward sensitive meeting content. The main risk is credential and data forwarding through an unverified intermediary rather than direct use of documented official APIs/SDKs.
Confidence: 86%Severity: 83%
Audit Metadata