jotform

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its Jotform-integration purpose, and the npm-based CLI install is more coherent than a raw download-execute chain. The main issue is data-flow integrity: all access is mediated through ClawLink, which stores its own credential locally and appears to hold the Jotform OAuth token server-side, creating meaningful third-party trust and credential-forwarding risk even though the skill is not clearly malicious.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:44 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fjotform%2F@e1501552463410df5454f4fc69956abfc25e0fcbbcaa8d67665bdc1d9071ac55
Security Audit — socket — jotform