add-dial

Warn

Audited by Socket on Aug 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is largely aligned with its stated Dial integration purpose and uses official same-org Dial tooling, so it is not clearly malicious. However, it combines curl|bash installation, direct manipulation of the Dial auth file, local command-target execution, nested skill installation, and optional agent-enabled calling/texting on a billed account; together these make the skill high-impact and medium-to-high security risk despite coherent purpose.

Confidence: 89%Severity: 71%
Audit Metadata
Analyzed At
Aug 30, 2026, 02:01 AM
Package URL
pkg:socket/skills-sh/nanocoai%2Fnanoclaw%2Fadd-dial%2F@458ac0aefe70c28812109a98acba28ca398bdf13922fd2bb71db047f6126c8a2
Security Audit — socket — add-dial