boldsign

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The install path appears same-org and reasonably verifiable, so this is not a clear supply-chain lure. However, the skill’s core design routes Boldsign access through ClawLink-hosted middleware that stores the provider OAuth token and intermediates all actions, which is a notable third-party trust and data-flow risk for an integration skill.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:43 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fboldsign%2F@f927de7be22530ab11d9ee3251ee23377cb7a414abefccff8598f80038a8fbe9
Security Audit — socket — boldsign