clawsec-clawhub-checker

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align: it wraps skill installation and adds security checks. Main concerns are supply-chain and transitive-trust: unpinned `npx ...@latest`, public-registry skill installs, and a setup script that patches another skill’s hooks. No clear credential harvesting, covert behavior, or off-platform data routing is evident from the provided text.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Apr 18, 2026, 03:50 PM
Package URL
pkg:socket/skills-sh/prompt-security%2Fclawsec%2Fclawsec-clawhub-checker%2F@91dbe21cd9c893475eb665f4e3da6c7ebe13621c