openai

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally consistent and uses a verifiable npm-distributed CLI, but its actual access model depends on ClawLink as a credential-holding intermediary rather than direct OpenAI API use. The main risk is third-party credential/data brokerage and broad action capability, not confirmed malware.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fopenai%2F@51751e82c990f1e4be0ce18030b630b8cdb31c41b9e6ca0d45a0b2b6641806dd
Security Audit — socket — openai