intercom
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s stated Intercom purpose is coherent, and the npm-based CLI source appears plausibly same-org, but the core design routes Intercom authentication and data through ClawLink as a third-party intermediary. That creates meaningful credential-forwarding and data-flow risk, especially because the skill enables authenticated write actions in a real external service.
Confidence: 88%Severity: 68%
Audit Metadata