manage-bap-backup

Fail

Audited by Socket on Mar 14, 2026

1 alert found:

Malware
MalwareHIGH
.clawnet/unsigned-skill.json

The code fragment is highly suspicious due to an opaque hex payload accompanied by signature and identity-related metadata. While no runtime code is present, the payload could drive sensitive operations once decoded by downstream components. Recommend safe decoding in an isolated environment, rigorous provenance verification (signature verification against trusted keys), and auditing of any downstream usage that could trigger network activity or identity export. Until decoding results are confirmed benign, treat as a medium-to-high risk and limit integration.

Confidence: 56%Severity: 85%
Audit Metadata
Analyzed At
Mar 14, 2026, 03:55 PM
Package URL
pkg:socket/skills-sh/b-open-io%2Fbsv-skills%2Fmanage-bap-backup%2F@929426be3b32c40e1a3bb6c647d4f4762fb2e228