openclaw-docs-audit

Warn

Audited by Socket on Mar 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose (upstream drift audit) is coherent with its data flows and sources. However, the install path relies on a direct curl | bash to a remote installer, which is a high-risk supply-chain pattern and unverifiable in terms of provenance. This creates a significant risk that the tool's footprint could extend beyond auditing if the installer is compromised or tampered with. Overall, the capability set is partially aligned but the install/execution pattern is disproportionate and warrants caution. Treat as SUSPICIOUS to HIGH-RISK due to download-and-execute vector; mitigate by pinning/installing from official registries or verified checksums, and by ensuring the installer is signed and verifiable.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 10, 2026, 02:40 PM
Package URL
pkg:socket/skills-sh/build000r%2Fskills%2Fopenclaw-docs-audit%2F@c41c57c4d63f425d1c2426139e9cb27075f54e9e