clawpilot-pair

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, but it asks the agent to install and execute globally-scoped npm CLIs from only partially verified publishers, including unpinned `@latest` versions, before producing a live pairing code. No clear credential harvesting or off-platform proxying is shown, so this is not confirmed malware, but the install-and-execute trust model is broader than ideal for a pairing workflow.

Confidence: 77%Severity: 63%
Audit Metadata
Analyzed At
May 5, 2026, 02:53 PM
Package URL
pkg:socket/skills-sh/Rethinking-studio%2Fclawpilot-skills%2Fclawpilot-pair%2F@b81a7eed604d2ce69876026e5d37cb2935803226