openclaw-config
Warn
Audited by Socket on Mar 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the runbook is largely coherent for OpenClaw operations, but it is over-broad for a config skill and includes sensitive credential/transcript access, transitive skill installation, and autonomous action patterns. No direct third-party credential exfiltration is shown, so this is not confirmed malware.
Confidence: 85%Severity: 66%
Audit Metadata