clawhub
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is a skill manager, but it depends on an unverifiable external helper distributed via a password-protected archive and a glot.io paste-into-terminal script, both far outside normal install trust for a registry CLI. Its transitive skill-install behavior further expands risk by pulling unreviewed skills into the agent.
Confidence: 92%Severity: 92%
Audit Metadata