etsy-tony-full-listing

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/clawlist_optimize.py

The code is an Etsy optimization API client with no evident malware such as persistence, sabotage, shell execution, cryptomining, or covert system-data theft. However, it deliberately transmits the CLAWLIST_API_KEY, product data, confirmed claims, competitor evidence, and potentially local image contents to the hard-coded third-party clawlist.best service. This creates a significant supply-chain and confidentiality risk unless that provider is trusted and the data transfer is explicitly authorized. The fragment also contains syntax errors and cannot run as provided.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Sep 17, 2026, 03:47 AM
Package URL
pkg:socket/skills-sh/tony11081%2Fetsy-tony-skills-full%2Fetsy-tony-full-listing%2F@2056a46fdfd3e470439481c4ac4371dcd9177e325cf1e57e10207bc9700b90cd
Security Audit — socket — etsy-tony-full-listing