hunter

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose matches Hunter automation, and the npm-based CLI appears same-publisher and officially documented, so this is not confirmed malware. However, the core model is a third-party gateway: ClawLink stores the Hunter OAuth token, the agent stores a reusable ClawLink credential, and all Hunter data/actions are routed through ClawLink rather than Hunter directly. That intermediary credential and data flow is disproportionate enough to rate as medium-high security risk.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fhunter%2F@9ca37352106861a216193b3888affdfb3937b37aeaa199304e8e6f9fe418ca91
Security Audit — socket — hunter