openclaw-config

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the runbook is largely coherent for OpenClaw operations, but it is over-broad for a config skill and includes sensitive credential/transcript access, transitive skill installation, and autonomous action patterns. No direct third-party credential exfiltration is shown, so this is not confirmed malware.

Confidence: 85%Severity: 66%
Audit Metadata
Analyzed At
Mar 15, 2026, 10:18 PM
Package URL
pkg:socket/skills-sh/adisinghstudent%2Fara.so%2Fopenclaw-config%2F@5324109e33e114ddcfd53b942c62b07088a33d96