tinypng

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent as a ClawLink-based TinyPNG connector, and its install path is relatively trustworthy via same-org npm/GitHub artifacts. The main risk is architectural: all TinyPNG access is mediated by ClawLink, so credentials, requests, and possibly storage parameters flow through a third party instead of official TinyPNG endpoints.

Confidence: 85%Severity: 63%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:46 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Ftinypng%2F@b6394c729e3d0c5ce9a35936c6e6f1ee5cd63309f8b8c15b60e5df1161a559c8
Security Audit — socket — tinypng