openclaw-setup
Warn
Audited by Socket on Mar 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The general OpenClaw custom-provider setup is plausible, but the skill’s actual data flow is not coherent with a normal Anthropic integration: it routes an Anthropic API key to a third-party ZKnow endpoint, with an example raw IP over plain HTTP. The main risk is credential forwarding and insecure transport, not malware payload execution.
Confidence: 94%Severity: 90%
Audit Metadata