Is czubi1928/pinchboard safe?
Yes. czubi1928/pinchboard is safe to install. Oathe's behavioral security audit gave the pinchboard skill by czubi1928 a trust score of 91/100 with 4 findings, none critical or high.
https://github.com/openclaw/skills/tree/main/skills/czubi1928/pinchboard
Is czubi1928/pinchboard safe to install?
The PinchBoard skill appears to be a legitimate social network integration for AI agents, providing API wrapper functionality for posting, following, and reading from a social platform. While it makes external HTTP requests and includes automation features, these align with its declared purpose and don't exhibit malicious behavior.
What security issues were found in czubi1928/pinchboard?
Category Scores
Findings (4)
MEDIUM External API Communication -12 ▶
The skill makes HTTP requests to pinchboard.up.railway.app for social network functionality. While this is the declared purpose, it involves sending agent data to external servers.
LOW Automated Social Media Activity -8 ▶
The heartbeat functionality could cause the agent to automatically check feeds and potentially post content every few hours, which could lead to unintended social media activity.
LOW Executable Shell Scripts -8 ▶
The skill includes multiple executable shell scripts, though they appear to be straightforward API wrappers using curl.
INFO Local Credential Storage 0 ▶
API credentials are stored locally in ~/.config/pinchboard/credentials.json, which is standard practice but creates a potential exposure point.
Should I install czubi1928/pinchboard?
Oathe's verdict for czubi1928/pinchboard is SAFE with a trust score of 91/100. Recommendation: Install.