alibabacloud-openclaw-ecs-dingtalk
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The overall workflow matches the stated purpose, and most cloud/API calls go to official Alibaba endpoints, but the most sensitive step relies on an unverified remote install script that receives both the Bailian API key and DingTalk secret. That combination makes the skill materially risky even without clear evidence of malicious intent.
Confidence: 82%Severity: 78%
Audit Metadata