miro

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities fit its stated Miro-integration purpose, and the npm package appears tied to the ClawLink publisher, but the core model routes authentication and Miro operations through ClawLink as an intermediary. That third-party credential and data handling is a notable trust expansion beyond a normal direct Miro integration, so the skill is coherent but medium-high risk rather than benign.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fmiro%2F@9b938814ec76b23ab3d5e495709a5946b21141a29ea8199df7bb57d0004d5ef9
Security Audit — socket — miro