claw-deck

Warn

Audited by Socket on Apr 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is mostly coherent with its stated workspace-management purpose and routes data to the expected Felo service, but its install flow is a notable trust problem: it tells the agent to execute a user-pasted GitHub install link without verification and contradicts its own prerequisite that the package should already be installed. Overall this is better classified as suspicious than benign due to install-trust inconsistency, not because of clear malicious exfiltration.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 12, 2026, 03:58 AM
Package URL
pkg:socket/skills-sh/Felo-Inc%2Ffelo-skills%2Fclaw-deck%2F@28b1722751c3734707a3b2fdc2e9d95178fe32d9