xai

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aligns with its stated purpose of chatting with Grok models via the xAI API and supporting vision and search features. The footprint is largely standard for a cloud-based AI integration. Main concerns are typical credential handling (API keys) and potential prompt/log exposure; no unverifiable binaries or outbound data to unknown endpoints are evident. Security posture is moderate; implement secret-handling best practices (mask logs, use secret storage), monitor logs for sensitive data, and ensure TLS and official endpoints are used. No indication of autonomous real-world actions or credential forwarding beyond normal API usage.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 07:56 AM
Package URL
pkg:socket/skills-sh/mvanhorn%2Fclawdbot-skill-xai%2Fxai%2F@1a407cecd8b6af057183cb47ee427d1ebb74a2c5