dialpad
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's Dialpad purpose is plausible, but its actual footprint depends on a third-party broker (ClawLink) that stores OAuth access and mediates all actions. The install source appears verifiably same-org and open source, so this is not confirmed malware, but credential centralization, intermediary data flow, unpinned `npx` execution, and real-world action capability make it a medium/high-risk integration skill.
Confidence: 85%Severity: 69%
Audit Metadata