linkhut

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s behavior mostly matches its stated purpose, but it routes Linkhut access through a third-party intermediary and a runtime-fetched CLI, expanding trust and credential exposure beyond a direct integration. This looks more like a hosted proxy connector than a native Linkhut skill, so the main concern is intermediary trust and credential forwarding rather than confirmed malware.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Flinkhut%2F@23d92b8d06947c961088ab0e68adf0bf7b304a0a4777a9cf61741da1b8db4c42
Security Audit — socket — linkhut