openclaw-extend

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN with elevated operational risk. The skill is internally consistent with its stated purpose as an OpenClaw extension operator, and the referenced CLI behavior matches official OpenClaw documentation. The main concerns are proportional but significant: broad plugin/hook supply-chain exposure, transitive trust in third-party extensions, and powerful remote node actions with real-world consequences. This looks like a legitimate admin skill rather than malware, but it should be treated as high-trust infrastructure tooling.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:57 PM
Package URL
pkg:socket/skills-sh/anthemflynn%2Fccmp%2Fopenclaw-extend%2F@a8f9e9336ca6d4969a771eed5eb1bddc07762e22