graincrawl

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities generally match its archive/search purpose, but install trust is weakened by a provenance mismatch between the stated publisher (`openclaw`) and the Go module source (`vincentkoc`), plus an unpinned `@latest` external CLI. Data access appears proportionate, and there is no direct evidence of credential theft or malicious exfiltration, but the binary’s trust chain is not internally consistent enough to rate fully benign.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
May 20, 2026, 04:22 PM
Package URL
pkg:socket/skills-sh/steipete%2Fclawdis%2Fgraincrawl%2F@9d8b53aa0334186654e746a2cc06e317f57c853b
Security Audit — socket — graincrawl