clawdirect-dev

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: largely coherent as a developer guide for ATXP/MCP web apps, but it includes transitive skill installation, remote CLI usage, URL-based cookie bootstrap that can expose auth tokens, and agent-driven external mutations on claw.direct. The behavior fits the stated purpose, yet the trust expansion and token-in-query pattern make it medium risk rather than benign.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/napoleond%2Fclawdirect%2Fclawdirect-dev%2F@79b9f63b631fcee06de9cceff1394ed781732e1d