clawshire-doc-extract-engine

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

该技能的能力与“PDF 结构化提取”目的基本一致,未见明显恶意载荷、远程安装链或隐蔽执行。但它要求将敏感文档和 API Key 发送到一个缺乏公开可验证官方资料的外部域名,并允许自定义 Base URL,整体更像中等风险的外部 SaaS 集成而非明确恶意。分类为 SUSPICIOUS。

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 6, 2026, 04:04 AM
Package URL
pkg:socket/skills-sh/lihanghang%2Fclawshire-open-skill%2Fclawshire-doc-extract-engine%2F@34a72ebc03d710c941ee99755cb4e0080d6dc93b