pushbullet

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent with its stated purpose, and the install source appears official enough for low supply-chain concern. The main risk is architectural: all Pushbullet access is brokered through ClawLink, which stores provider OAuth tokens and receives action data, so credentials and actions are routed through a third-party intermediary rather than Pushbullet directly.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fpushbullet%2F@75289e7bcd63a8b6a099ba2fca04d2d8dd74d55429f57897c6d5a6ee735bfad4
Security Audit — socket — pushbullet