clawcard

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is internally consistent with its stated purpose, but that purpose is itself high impact. It grants autonomous messaging, financial spending, card retrieval, and hosted secret storage, while instructing the agent to read a local API key file and send sensitive data to a third-party platform. This is not clearly malicious, but it is a high-risk skill that should require strong user approval and tight operational controls.

Confidence: 88%Severity: 86%
Audit Metadata
Analyzed At
Mar 16, 2026, 03:11 AM
Package URL
pkg:socket/skills-sh/latchagent%2Fskill%2Fclawcard%2F@9f4042e02c3559214332b9b95374711708cd4626