cold-start
Warn
Audited by Socket on Aug 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core purpose is coherent for a data-bootstrap skill, and the offline Takeout path is proportionate. However, the live-sync design routes highly sensitive personal data and delegated authority through ClawVisor instead of official service APIs, asks for expansive cross-account scope, and chains to additional skills. This is not confirmed malware, but it creates a high privacy and trust risk that is disproportionate unless the user explicitly accepts a third-party credential gateway.
Confidence: 90%Severity: 76%
Audit Metadata