Skip to main content

pp-company-goat

Enables in-depth research on startups using SEC Form D and other sources, providing valuable insights without the cost of premium services.

Install this skill

or
85/100

Security score

The pp-company-goat skill was audited on Jun 6, 2026 and we found 3 security issues across 2 threat categories. Review the findings below before installing.

Categories Tested

Security Issues

medium line 262

Webhook reference - potential data exfiltration

SourceSKILL.md
262| `webhook:<url>` | POST the output body to the URL (`application/json` or `application/x-ndjson` when `--compact`) |
medium line 264

Webhook reference - potential data exfiltration

SourceSKILL.md
264Unknown schemes are refused with a structured error naming the supported set. Webhook failures return non-zero and log the URL + HTTP status on stderr.
medium line 250

Access to hidden dotfiles in home directory

SourceSKILL.md
250Entries are stored locally at `~/.company-goat-pp-cli/feedback.jsonl`. They are never POSTed unless `COMPANY_FEEDBACK_ENDPOINT` is set AND either `--send` is passed or `COMPANY_FEEDBACK_AUTO_SEND=true
Scanned on Jun 6, 2026
View Security Dashboard
Installation guide →