crabbox

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, and the same-org Crabbox tooling appears legitimate, but the overall footprint is high-trust and expansive. It forwards secrets to remote environments, syncs repo data off-host, supports SSH/desktop control, and relies on an official yet third-party Blacksmith CLI installed via curl|sh with auto-update. This looks more like a powerful remote orchestration skill than malware, but it carries meaningful security risk and should only be used with tightly controlled credentials and explicit user intent.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Aug 1, 2026, 08:34 AM
Package URL
pkg:socket/skills-sh/openclaw%2Flobster%2Fcrabbox%2F@aa9a667506df0c93c741b21ddf27e839780f1987bea044c5f3eb09731a007d95
Security Audit — socket — crabbox