clawnet-cli
Fail
Audited by Socket on Apr 1, 2026
1 alert found:
Obfuscated FileObfuscated File.clawnet/unsigned-skill.json
HIGHObfuscated FileHIGH
.clawnet/unsigned-skill.json
This fragment does not contain executable code, so direct malware behaviors (exfiltration, credential theft, reverse shells, or persistence actions) cannot be confirmed. The main risk signal is that it is a heavily encoded, signature-associated on-chain/ord-style artifact containing embedded text with unusual vault/decryption/evasion/backdoor-adjacent claims. To assess real supply-chain risk, the missing package runtime/installer code that could decode and act on these embedded payloads must be reviewed.
Confidence: 85%
Audit Metadata