jqopenclaw-node-invoker
Audited by Socket on Mar 10, 2026
1 alert found:
Obfuscated FileThe skill appears to be a coherent, high-privilege gateway invoker for a predefined set of node capabilities. Its footprint is large but aligns with its stated purpose of orchestrating remote file, process, and system operations through a controlled node.invoke interface. The design relies on gateway policies and explicit parameter controls to mitigate abuse. Given the lack of explicit unverifiable binaries or external exfiltration paths in the provided description, the risk is elevated due to the breadth of capabilities but remains within an expected scope for a specialized management tool. Overall, the skill is SUSPICIOUS-to-BENIGN in balance; it should be treated as SUSPICIOUS due to potential privilege abuse if misconfigured, but not malicious based on the static description alone.