ahrefs

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's Ahrefs-focused capabilities are coherent, and the npm-based CLI install is not inherently malicious. However, the core integration depends on a third-party intermediary that stores tokens and brokers all Ahrefs access, which creates significant data-flow and credential-trust risk beyond a direct official Ahrefs integration.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:43 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fahrefs%2F@122d1a6c2f65f3839d601731bfed9ff35edf6194ee8ef7adccf454825f68933e
Security Audit — socket — ahrefs