waybackclaw

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
catalog.json

The fragment is service-integration metadata rather than malware code. It intentionally sends an agent token and financial decision data to waybackclaw.space and directs installation from an unreviewed external GitHub repository. No direct malicious payload is present in the supplied content, but the token-handling, third-party data disclosure, possible real-fund x402 calls, and lack of repository pinning warrant review before use. Assessment of the installed skill requires the referenced repository contents.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 9, 2026, 08:48 AM
Package URL
pkg:socket/skills-sh/bankrbot%2Fskills%2Fwaybackclaw%2F@13a9198e1a669ef56996328811625fcb72d22d4b3d8ae992c991af6509f96203
Security Audit — socket — waybackclaw