bounty-hunter-starter

Warn

Audited by Socket on Mar 20, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is plausible, but the installation method is disproportionate for a rules/workflow skill. The main risk is supply-chain trust: an unreviewed install.sh from a personal repo, outside the official OpenClaw installation path, with no verification or provenance evidence. No direct credential theft or malicious data exfiltration is visible from the provided text, but the install boundary is too opaque to treat as benign.

Confidence: 83%Severity: 78%
SecurityMEDIUM
skills/bounty-hunter-starter/SKILL.md

SUSPICIOUS: the stated purpose is a benign OpenClaw rules pack, but the actual install path relies on unverified shell scripts from a personal GitHub repo and does not match the official documented skill installation method. No direct credential theft or exfiltration is shown in the provided text, so this is not confirmed malware, but the opaque download-and-execute footprint is disproportionate for a configuration/rules skill.

Confidence: 83%Severity: 76%
Audit Metadata
Analyzed At
Mar 20, 2026, 06:40 AM
Package URL
pkg:socket/skills-sh/henryatulike-bot%2Fbounty-hunter-starter-pack%2Fbounty-hunter-starter%2F@dba4f4a2d58cbc35dbc32ac4c50f3ae9123795bd