unclawg-feed

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The business purpose is coherent, but the trust model is not: the skill requires an unverifiable uc_feed wrapper and forwards high-value OpenClaw machine credentials to it. That black-box dependency plus raw .env secret loading creates disproportionate supply-chain and credential-handling risk even though the API workflow itself appears aligned to approval routing.

Confidence: 84%Severity: 86%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:13 PM
Package URL
pkg:socket/skills-sh/build000r%2Fskills%2Funclawg-feed%2F@3559859cb435f3b0a29e72e2f063c41cc4fec203