render

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the CLI provenance appears same-org and source-visible, so this is not strong malware evidence. However, the integration routes Render access and tokens through ClawLink as a third-party intermediary and enables write actions on infrastructure, creating medium security risk from credential mediation and indirect data flow.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:46 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Frender%2F@9117febf2e5e35da11fb3283bde726d33e617863b037db3eaa2ad3c1de4c9272
Security Audit — socket — render