clawhub
Warn
Audited by Socket on Apr 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS due to transitive skill installation and unpinned remote CLI execution, not because of obvious credential theft or mismatched purpose. The skill is coherent with its stated registry/install purpose and appears to use same-project official infrastructure, but it materially expands agent trust by fetching and loading third-party skills from a public registry.
Confidence: 90%Severity: 68%
Audit Metadata