add-deltachat

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent for adding a DeltaChat channel, and its credential/data flows are broadly proportional to that purpose. The main concerns are supply-chain trust: unverified code copied from the user's `origin` branch and a pinned npm package that may include prebuilt binaries without checksum/signature verification; plaintext transport is also optionally allowed. I do not see strong evidence of deliberate credential theft or unrelated exfiltration.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
May 4, 2026, 07:54 PM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw%2Fadd-deltachat%2F@bfaed17bd0812f366fe44d60dc5b0a1c998defe4