clay-reference-architecture

Warn

Audited by Socket on Feb 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected This skill is a benign reference architecture for integrating with the Clay SDK. I find no evidence of malicious code, obfuscation, or credential-harvesting behavior in the provided content. The main security issues are operational: example guidance stores apiKey in local JSON (insecure for production) and a dynamic require uses NODE_ENV which should be validated. Recommend using environment variables or secret management, validate NODE_ENV, and audit actual ClayClient/Monitor implementations for where credentials or telemetry are sent. LLM verification: BENIGN: The skill fragment coherently describes a reference architecture with components and data flows appropriate for its stated purpose. While dynamic configuration loading via environment-driven file paths is present, it is a standard practice in configuration management and does not indicate malicious intent or harmful data flow. No credentials are hardcoded, and no illicit data flows are evident from the fragment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 20, 2026, 05:29 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Fclaude-code-plugins-plus-skills%2Fclay-reference-architecture%2F@90a82bdf7a6d95a7464e7922255fce8d4bc492c6