picoclaw-ai-assistant

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, and the web/API credentials are proportionate for an AI assistant, but the main risk is install trust: the skill is published by ara.so while execution depends on downloading and running a third-party precompiled binary from the sipeed GitHub repo. Data flows are otherwise consistent with the stated assistant function, with no clear credential exfiltration or hidden behavior shown in the skill text.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
Sep 12, 2026, 08:38 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Ftrending-skills%2Fpicoclaw-ai-assistant%2F@5b972ad337e0570eaf3b07159c901502b1107472c82f40f853c3f003956690b3
Security Audit — socket — picoclaw-ai-assistant