openclaw-stock-skill

Fail

Audited by Snyk on Jul 18, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). The bundle directs installation via npx/git to an unverified GitHub repository owned by a numeric/unknown account (https://github.com/1018466411/openclaw-stock-data-skill), which is a high-risk vector because installing code from an untrusted GitHub user can execute arbitrary/malicious code.

Issues (1)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 18, 2026, 10:58 PM
Issues
1
Security Audit — snyk — openclaw-stock-skill