waybackclaw
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalycatalog.json
LOWAnomalyLOW
catalog.json
The fragment is service-integration metadata rather than malware code. It intentionally sends an agent token and financial decision data to waybackclaw.space and directs installation from an unreviewed external GitHub repository. No direct malicious payload is present in the supplied content, but the token-handling, third-party data disclosure, possible real-fund x402 calls, and lack of repository pinning warrant review before use. Assessment of the installed skill requires the referenced repository contents.
Confidence: 97%Severity: 58%
Audit Metadata