yandex

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches its commands and the CLI appears to come from an official same-org npm/repo trail, so this is not overt malware. The main concern is data-flow integrity: Yandex access is proxied through ClawLink, which holds OAuth tokens and intermediates actions instead of using direct official Yandex APIs from the agent.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fyandex%2F@72d423dc563b3dc4ee566b6fcc4f3c00135833d7bc37cfee46b724de4278ed78
Security Audit — socket — yandex