unclawg-internet
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose matches onboarding and agent provisioning, and the unclawg.com/api.unclawg.com endpoints appear purpose-consistent. However, the required uc_onboard wrapper is an unverifiable external binary in the provided material, and this workflow forwards highly sensitive tokens and machine-key secrets through that trust boundary and into local files/browser URLs. The skill is coherent in function but high risk in execution trust and credential handling.
Confidence: 84%Severity: 83%
Audit Metadata