clawbazaar-skill

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The crypto/NFT capabilities match the stated purpose, but the trust and data-flow model is risky: an unverifiable bundled CLI is built locally, configuration instructs fetching material over insecure HTTP, and the skill normalizes passing wallet private keys to both CLI and backend APIs for marketplace actions. This is coherent with a marketplace tool but still high risk due to credential exposure and financial-action scope.

Confidence: 84%Severity: 86%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:59 PM
Package URL
pkg:socket/skills-sh/motimilo%2Fclawbazaar-agents-art-and-goods%2Fclawbazaar-skill%2F@4fc548fe9d906220b89af471a9b667c677968616