humanloop
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's Humanloop purpose is coherent, but it depends on a third-party intermediary CLI and hosted credential/token flow rather than direct Humanloop APIs. The main concerns are runtime execution of an external npm CLI, local storage of a ClawLink credential, and routing Humanloop access through ClawLink; this is medium risk rather than confirmed malware.
Confidence: 81%Severity: 61%
Audit Metadata