tinypng
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is internally coherent as a ClawLink-based TinyPNG connector, and its install path is relatively trustworthy via same-org npm/GitHub artifacts. The main risk is architectural: all TinyPNG access is mediated by ClawLink, so credentials, requests, and possibly storage parameters flow through a third party instead of official TinyPNG endpoints.
Confidence: 85%Severity: 63%
Audit Metadata