openclaw-user-profiler

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core profiling and local file-write behavior is coherent with the stated purpose and shows no credential theft or exfiltration. The main risk is proportional but real: this skill recommends and facilitates transitive installation of additional skills via an external CLI and unpinned package identifiers from third-party sources, which raises supply-chain risk even though the skill itself is not overtly malicious.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
May 2, 2026, 11:42 PM
Package URL
pkg:socket/skills-sh/eamanc-lab%2Fopenclaw-persona-forge%2Fopenclaw-user-profiler%2F@6be4eeb81a2b76b91d54c98e60302e5c2aee89c6