fathom

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is plausible for a Fathom integration, but the core dependency is an unverifiable `fathom` CLI that receives API keys and can export or forward sensitive meeting content. The main risk is credential and data forwarding through an unverified intermediary rather than direct use of documented official APIs/SDKs.

Confidence: 86%Severity: 83%
Audit Metadata
Analyzed At
Mar 16, 2026, 11:14 PM
Package URL
pkg:socket/skills-sh/danielgwilson%2Ffathom-cli%2Ffathom%2F@e9caafdf1a2d4569ba90c2f00f589b239871dbbd