bear-notes

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities fit Bear note management, but its trust model is weaker than ideal because it installs an unpinned third-party CLI from a personal GitHub repo and forwards a Bear API token to that tool. Data flows appear locally consistent with Bear's x-callback API rather than overt exfiltration, so this is not confirmed malicious, but the external credential-handling dependency makes it medium risk.

Confidence: 89%Severity: 66%
Audit Metadata
Analyzed At
Mar 14, 2026, 12:14 AM
Package URL
pkg:socket/skills-sh/linuxhsj%2Fopenclaw-zero-token%2Fbear-notes%2F@87b7c75852b393e480eea9092f1c80f9f9353b7b