alibabacloud-openclaw-ecs-dingtalk

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The overall workflow matches the stated purpose, and most cloud/API calls go to official Alibaba endpoints, but the most sensitive step relies on an unverified remote install script that receives both the Bailian API key and DingTalk secret. That combination makes the skill materially risky even without clear evidence of malicious intent.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
Apr 1, 2026, 08:40 AM
Package URL
pkg:socket/skills-sh/aliyun%2Falibabacloud-aiops-skills%2Falibabacloud-openclaw-ecs-dingtalk%2F@a6bbc033c54b2b47b86e888e87b9cac161775c61