bear-notes

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities match its stated Bear-notes purpose and its data flows are mostly consistent with Bear's documented x-callback-url API, but it relies on an unpinned third-party CLI from a personal GitHub repo and forwards a Bear token to that tool. This is not clearly malicious, but the install trust and credential-forwarding footprint are broader than an official Bear integration would be.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:44 PM
Package URL
pkg:socket/skills-sh/elizaos%2Feliza%2Fbear-notes%2F@2603323807b4b0075263f1f69abf3fd2933f0cce