api-provider-setup
Warn
Audited by Socket on Apr 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s stated purpose matches config editing for OpenClaw, but its actual data flow normalizes forwarding API keys and model traffic to third-party relay/proxy domains rather than official provider endpoints. The unverifiable local sync script and direct handling of cached auth files add risk, though there is no clear exploit payload or confirmed malware.
Confidence: 91%Severity: 83%
Audit Metadata