gateway

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities largely match its stated purpose as a local gateway-operations skill, and its multi-channel/network behavior is expected for that role. Main concerns are partial provenance for the `joelclaw` CLI, broad local/context access, and meaningful prompt-injection/autonomous-action exposure from an always-on daemon that processes external messages. No clear evidence of credential theft, deceptive routing, or overt malware.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:59 PM
Package URL
pkg:socket/skills-sh/joelhooks%2Fjoelclaw%2Fgateway%2F@c1a6cad33b57da80b550bdd104c6392fde2c659b