openclaw-setup

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill fragment is coherently aligned with its stated purpose of guiding installation, deployment, and usage of OpenClaw. It relies on standard, well-known distribution channels (npm, official docs) and references. No malicious data flows or credential handling are evident within the fragment itself. The primary security considerations are general supply-chain risks associated with npm-packaged tooling and ensuring the underlying openclaw package is trusted and up-to-date. Overall, the material is benign with moderate supply-chain risk typical of CLI tooling distributed via npm.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:56 AM
Package URL
pkg:socket/skills-sh/iofficeai%2Faionui%2Fopenclaw-setup%2F@91871342c897803caffa0eebff69a77eb90b8d3a