clawsec-scanner

Warn

Audited by Socket on May 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Mostly purpose-aligned security tooling, not a clear credential-harvesting skill. Main risks come from executing untrusted hook code during DAST, event-driven autonomous scans, and recommended transitive installation via clawhub; overall suspicious/high-risk from an agent-safety standpoint but not confirmed malware.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
May 15, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/prompt-security%2Fclawsec%2Fclawsec-scanner%2F@9a618fdfa5a71187e0f6468812da32ca38c6a803