unclawg-internet
Warn
Audited by Socket on Apr 10, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill’s purpose largely matches its capabilities, and most data flows target same-brand Unclawg endpoints, but the required uc_onboard wrapper is an unverifiable binary that handles auth tokens and machine-key secrets. That alone drives high security risk under the scoring rules; the unclear publisher/install chain and token-in-URL callback further increase concern.
Confidence: 84%Severity: 85%
Audit Metadata