box

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The package source appears reasonably attributable to ClawLink, so this is not primarily a supply-chain malware case. However, the skill's core design routes Box access, tokens, and actions through ClawLink's hosted intermediary rather than direct Box APIs, and it grants broad Box administrative capabilities via that gateway. That makes the data flow and credential model higher risk than a normal first-party Box integration.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:43 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fbox%2F@53052479d33e4c9a5b6520af80a9cb8a71b9d9e937a3ccafe63a36e6feea7194
Security Audit — socket — box