recruitment

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated recruitment purpose is plausible, but the execution path is not proportionate or trustworthy: it runs an unpinned third-party proxy, forwards the CRAFTED_API_KEY through that proxy, and sends traffic to a non-Crafted bore.pub HTTP tunnel with no TLS. This is a major install-trust and data-flow integrity failure, with clear credential exposure risk.

Confidence: 96%Severity: 95%
Audit Metadata
Analyzed At
Mar 17, 2026, 07:06 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Frecruitment%2F@656572ad9852b8235edabbf377e184226effd4f8