Customer Support Operations Engine
Audited by Socket on Feb 21, 2026
1 alert found:
Malware[Skill Scanner] Natural language instruction to download and install from URL detected This file is a benign, comprehensive customer support operations playbook and templates. It contains no executable code, no requests for credentials, and no obvious malicious behaviors. The only supply-chain concern is the presence of an install command and links to third-party hosted context packs — following those may fetch external code and should be treated with normal caution (verify source, pin versions, inspect code before running). Overall: documentation is internally consistent with its purpose and does not itself contain malware or credential-harvesting behavior. LLM verification: The file itself is documentation for a customer-support AI skill and contains a rich set of templates and playbooks. There is no direct code-level malware observable in the provided document. The main security finding is a moderate supply-chain risk: the explicit non-standard install instruction (`clawhub install afrexai-support-operations`) and linked third-party sites allow an operator to fetch and execute external artifacts without built-in provenance or verification information. Treat the in