botlearn-healthcheck

Warn

Audited by Socket on Mar 7, 2026

1 alert found:

Anomaly
AnomalyLOW
data_collect.md

This protocol is a comprehensive local-diagnostic data collection plan for OpenClaw that legitimately gathers status, config, logs, tasks, and workspace artifacts into DATA.* context keys. The content itself does not contain obfuscated or directly malicious code. However, executing package-provided shell scripts and running `openclaw doctor --deep` constitute a meaningful supply-chain risk: if any of those scripts or local files were tampered with, they could execute arbitrary commands, read secrets, or exfiltrate data captured into the DATA.* store. The protocol takes some precautions (not reading identity file contents, redacting common secret patterns) but lacks stronger safeguards (signing, sandboxing, least-privilege execution, and robust redaction). Recommend treating the environment as potentially untrusted, verifying integrity of scripts/configs before running, and restricting collection of sensitive environment variables and files.

Confidence: 80%Severity: 60%
Audit Metadata
Analyzed At
Mar 7, 2026, 02:30 AM
Package URL
pkg:socket/skills-sh/botlearn-ai%2Fbotlearn-skills%2Fbotlearn-healthcheck%2F@93b154375729464673057b455f6175f7d26b3f33