instagram

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's Instagram purpose matches its capabilities, and the installer appears to come from the same publisher via npm, so this is not overt malware. However, it routes Instagram access and tokens through ClawLink rather than direct official API use, stores a reusable local credential, executes an unpinned third-party CLI, and enables autonomous public posting/commenting. The footprint is coherent but introduces meaningful trust and data-flow risk.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:46 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Finstagram%2F@68adc34de69418bbb21e9a9a37e2a44314f129569a42860d2b4773c587005ec3
Security Audit — socket — instagram