OpenClaw

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The OpenClaw guide is largely coherent with its stated purpose of providing installation, configuration, and usage steps for a Discord-enabled gateway. The footprint is modest and focused on legitimate developer tooling. The primary security consideration is credential handling: the bot token is stored in a local JSON file and could be exposed via logs or improper file permissions. There are no evident download-and-execute supply-chain patterns or autonomous real-world actions. Overall, the skill is BENIGN with moderate risk (primarily around credential exposure).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 03:14 AM
Package URL
pkg:socket/skills-sh/inclusionAI%2FAWorld%2Fopenclaw%2F@a332bfd55cf4365270b2ee5ba6bbf47e13ea0a50