lingzhu

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill appears to be a plausible integration layer between Lingzhu and Rokid Glasses, aligning with its stated purpose of controlling camera, navigation, and calendar via mapped OpenClaw tools. However, it introduces notable supply-chain and data-flow considerations: reliance on an external npm package without visible integrity validation, outbound gateway configuration, and the potential need for tokens or credentials not shown in the fragment. Overall, the footprint is coherent with the described purpose but leans toward moderate security risk due to installation from an external package and remote orchestration aspects. Treat as SUSPICIOUS until verified with package integrity, credentials handling details, and explicit data-flow diagrams.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 02:17 PM
Package URL
pkg:socket/skills-sh/EndlessJour9527%2Fopenclaw-lingzhu-skill%2Flingzhu%2F@7237ba7d05c91d30048e13b32ef4806be291007d