bear-notes

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent, and its token usage aligns with Bear's documented API, but it relies on an unofficial third-party CLI from a personal GitHub repo and forwards Bear credentials to that tool. This is a proportionate note-management skill with notable supply-chain and credential-trust concerns, not confirmed malware.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Aug 1, 2026, 08:32 AM
Package URL
pkg:socket/skills-sh/LinkupPlatform%2Fopenclaw%2Fbear-notes%2F@223a6fe787b0f96723dc40227e8696e8e8ccf121fcda06c9cd7ae9830790d2da
Security Audit — socket — bear-notes