drclaw
Warn
Audited by Socket on May 6, 2026
1 alert found:
AnomalyAnomalyskills/dr-claw/SKILL.md
LOWAnomalyLOW
skills/dr-claw/SKILL.md
SUSPICIOUS. The skill is mostly aligned with a local workflow-control purpose, but it weakens safety by requiring `--bypass-permissions`, enables autonomous outbound notifications, and relies on an unspecified local CLI/scripts whose provenance is not established in the skill text. No clear credential theft or attacker-controlled exfiltration endpoint is shown, so this is better classified as a high-risk vulnerable skill rather than confirmed malware.
Confidence: 83%Severity: 69%
Audit Metadata