qclaw-env

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities largely match its environment-installation purpose, but its trust model is too broad: it mandates remote installer execution and includes non-first-party mirror scripts for core package managers. No clear credential theft or exfiltration is present, so this is not confirmed malware, but it is a high supply-chain risk skill.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Mar 21, 2026, 04:46 PM
Package URL
pkg:socket/skills-sh/stvlynn%2Fqclaw-skills%2Fqclaw-env%2F@b575fc88dfe821c94eeee70659dc6e7180dedca3