openclaw-hivemind
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core behavior is mostly consistent with the stated purpose, but the skill asks the agent to read a raw Solana private-key file and send authentication data to a configurable workers.dev endpoint whose ownership is not strongly verifiable from the skill text. This looks more like a medium-risk messaging/auth plugin than malware, with the main concerns being credential handling and endpoint trust.
Confidence: 84%Severity: 56%
Audit Metadata