clip-skills

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The documented behavior is coherent for a local skill-registry manager and shows no credential theft, exfiltration, or remote API proxying. Risk comes from unverifiable `clip` CLI provenance and the transitive trust created by installing arbitrary skills into agents; absent official publisher/install evidence, this should be treated as medium risk rather than benign.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
May 9, 2026, 05:25 PM
Package URL
pkg:socket/skills-sh/ori-kim%2Fcli-proxy%2Fclip-skills%2F@084e155716788389927ca81a7d9f746515101088