humanloop

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's Humanloop purpose is coherent, but it depends on a third-party intermediary CLI and hosted credential/token flow rather than direct Humanloop APIs. The main concerns are runtime execution of an external npm CLI, local storage of a ClawLink credential, and routing Humanloop access through ClawLink; this is medium risk rather than confirmed malware.

Confidence: 81%Severity: 61%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fhumanloop%2F@d92302d50125c70a8dba193834fc6bcad4fcf631688a1d162715b4e6e446013a
Security Audit — socket — humanloop