syslog-receiver

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated capability is coherent for a syslog receiver, and there is no direct credential harvesting or exfiltration in the skill text. However, the required external component `syslog-mcp` is underspecified and not verifiably tied to the publisher, with no pinning or provenance guidance; that unresolved dependency trust gap drives the risk rating.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Jul 30, 2026, 04:31 PM
Package URL
pkg:socket/skills-sh/automateyournetwork%2Fnetclaw%2Fsyslog-receiver%2F@aae684ad157307c81fed48189e5d2879cc6e9acfe35fd9c3cf0015cda14895e3
Security Audit — socket — syslog-receiver