clawdhub

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The ClawdHub CLI skill is coherent with its stated purpose: it installs a legitimate CLI tool from npm, uses it to interact with a remote skill registry, and supports local skill management workflows (search/install/update/publish). Credentials are limited to the expected publish workflow, and data flows are consistent with a developer tooling scenario. No indicators of improper data exfiltration, stealth behavior, or malicious third-party payloads are evident from the provided content. The primary security concerns are typical for CLI-based developer tooling: dependency trust, proper handling of credentials, and explicit user consent for publish actions. Overall, the risk profile is low to moderate (securityRisk ~0.25) with no demonstrated malware. Recommend standard usage with attention to credential handling and network access controls.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 09:12 PM
Package URL
pkg:socket/skills-sh/ComposioHQ%2Fopenclaw-composio%2Fclawdhub%2F@e58865c615e1da5cc257b6630106cb9d60a8b98a