openclaw-setup

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The general OpenClaw custom-provider setup is plausible, but the skill’s actual data flow is not coherent with a normal Anthropic integration: it routes an Anthropic API key to a third-party ZKnow endpoint, with an example raw IP over plain HTTP. The main risk is credential forwarding and insecure transport, not malware payload execution.

Confidence: 94%Severity: 90%
Audit Metadata
Analyzed At
Mar 13, 2026, 03:06 AM
Package URL
pkg:socket/skills-sh/binjie09%2Fzknow-skills%2Fopenclaw-setup%2F@101efdff0acaa3a4f4618eb74d1091bd8d0c0d64