affinity

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, but it routes Affinity access, credentials, and CRM data through ClawLink as an intermediary rather than using official direct Affinity auth/API flows. The npm-delivered CLI appears same-brand and publicly documented, so this is not confirmed malware, but the third-party credential holding and data mediation make the security risk medium-high.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:43 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Faffinity%2F@443472b8c7c81dda86e266012421a00ba4f216cf9ced6d874c3346e229502de6
Security Audit — socket — affinity