openclaw-hivemind

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core behavior is mostly consistent with the stated purpose, but the skill asks the agent to read a raw Solana private-key file and send authentication data to a configurable workers.dev endpoint whose ownership is not strongly verifiable from the skill text. This looks more like a medium-risk messaging/auth plugin than malware, with the main concerns being credential handling and endpoint trust.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 2, 2026, 04:36 PM
Package URL
pkg:socket/skills-sh/GuiBibeau%2Fopenclaw-hivemind-protocol%2Fopenclaw-hivemind%2F@13a74e219898aeb0d3f51bb02496449271266600