dialpad

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's Dialpad purpose is plausible, but its actual footprint depends on a third-party broker (ClawLink) that stores OAuth access and mediates all actions. The install source appears verifiably same-org and open source, so this is not confirmed malware, but credential centralization, intermediary data flow, unpinned `npx` execution, and real-world action capability make it a medium/high-risk integration skill.

Confidence: 85%Severity: 69%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:44 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fdialpad%2F@185001e3886affd6ba410d8cd1bd3e30af91375bf1a6b49158bfeb160a62fad3
Security Audit — socket — dialpad