company-contact-finder

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior matches lead generation, and there is no explicit malware pattern, installer, or credential theft instruction. However, the skill routes queries through an unverifiable Gooseworks MCP intermediary rather than directly to the official Crustdata/SixtyFour APIs, creating medium supply-chain and data-flow risk due to unclear provenance and credential forwarding.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Mar 29, 2026, 05:17 PM
Package URL
pkg:socket/skills-sh/nikiandr%2Fgoose-skills%2Fcompany-contact-finder%2F@f64b34b5d2776175fb712480bc031923d1dc0a68