splitwise

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose is coherent, but its actual data flow routes Splitwise access through ClawLink as a third-party intermediary rather than direct official APIs. The npm-distributed CLI lowers pure supply-chain concern, yet the hosted proxy model and reusable local credential create meaningful privacy and account-action risk for a finance integration.

Confidence: 82%Severity: 66%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:46 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fsplitwise%2F@af84abd5ccd3c51eaba0b01b320880fa891b8a545087cfa1a048c0623ab848d3
Security Audit — socket — splitwise