openclaw-setup
Fail
Audited by Socket on Mar 4, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The skill fragment is coherently aligned with its stated purpose of guiding installation, deployment, and usage of OpenClaw. It relies on standard, well-known distribution channels (npm, official docs) and references. No malicious data flows or credential handling are evident within the fragment itself. The primary security considerations are general supply-chain risks associated with npm-packaged tooling and ensuring the underlying openclaw package is trusted and up-to-date. Overall, the material is benign with moderate supply-chain risk typical of CLI tooling distributed via npm.
Confidence: 95%Severity: 90%
Audit Metadata