wrike

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align, and the install source appears to be the publisher's npm package, but the core integration routes authentication and Wrike operations through ClawLink's third-party backend instead of Wrike's official direct API flow. That intermediary trust, local credential storage, unpinned `npx` execution, and potential hosted logging make the skill medium-risk even without clear evidence of malware.

Confidence: 85%Severity: 60%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:46 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fwrike%2F@d2cd76f3166eaa20494375ee3f678f9ba68047c25ebeae226e45297973385090
Security Audit — socket — wrike