clip-skills
Warn
Audited by Socket on May 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The documented behavior is coherent for a local skill-registry manager and shows no credential theft, exfiltration, or remote API proxying. Risk comes from unverifiable `clip` CLI provenance and the transitive trust created by installing arbitrary skills into agents; absent official publisher/install evidence, this should be treated as medium risk rather than benign.
Confidence: 85%Severity: 64%
Audit Metadata