shippo

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent for a Shippo-via-ClawLink integration, and the CLI provenance appears consistent with the publisher, so this is not confirmed malware. However, it materially expands trust by routing Shippo operations and credentials through ClawLink instead of direct official Shippo API use, while also enabling real-world write actions through an external CLI and hosted service.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fshippo%2F@abb97f0ff18f69946f58a0e38bda8f1da2e7bf4d3afe0e82753ecfaf2626a31a
Security Audit — socket — shippo