bitwarden

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose matches its capabilities, and data appears to flow to expected Bitwarden/Vaultwarden services through a publicly sourced CLI. But it routes master-password-derived access and all vault secrets through an unofficial third-party client and gives the agent broad access to extremely sensitive credentials, so the overall risk is medium rather than benign.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 09:11 PM
Package URL
pkg:socket/skills-sh/clawdbot%2Fskills%2Fbitwarden%2F@2eb5e009acc44cbb53e6afbab7a6baae5f870387
Security Audit — socket — bitwarden