pp-clockify
Warn
Audited by Socket on Jul 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is broadly aligned with Clockify automation, but its footprint is wider than its headline purpose and it depends on a third-party CLI that receives the user’s Clockify API key. Same-author provenance reduces concern versus a random installer, yet unpinned external installs, credential forwarding, arbitrary webhook delivery, and expansive write-capable Clockify actions make this a medium-high risk skill rather than benign.
Confidence: 86%Severity: 74%
Audit Metadata