boldsign
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The install path appears same-org and reasonably verifiable, so this is not a clear supply-chain lure. However, the skill’s core design routes Boldsign access through ClawLink-hosted middleware that stores the provider OAuth token and intermediates all actions, which is a notable third-party trust and data-flow risk for an integration skill.
Confidence: 84%Severity: 66%
Audit Metadata