shippo
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is internally coherent for a Shippo-via-ClawLink integration, and the CLI provenance appears consistent with the publisher, so this is not confirmed malware. However, it materially expands trust by routing Shippo operations and credentials through ClawLink instead of direct official Shippo API use, while also enabling real-world write actions through an external CLI and hosted service.
Confidence: 86%Severity: 58%
Audit Metadata