otter

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s high-level purpose is coherent, but it relies on raw Otter account credentials and an unverifiable unofficial API path even though Otter provides official API-key auth. Optional CRM sync is expected for the stated feature, but the missing script implementation leaves actual endpoints and credential handling unverified, raising medium-to-high security risk without proving confirmed malware.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Sep 2, 2026, 04:38 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fotter%2F@bb70886f3c8cdc0b58a2a5244e004de3a3df3af86c3bd1be1be4548373215d3b
Security Audit — socket — otter