ai-article

Fail

Audited by Socket on Mar 14, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/OpenClaw-install.md

The document is a pragmatic, user-focused installation guide that contains high-risk operational recommendations (pipe-to-shell installer, global npm installs, storing/pasting high-privilege secrets, granting broad IM permissions). There is no direct evidence in this text that the upstream artifacts are malicious, but following these instructions without defensive measures substantially raises the risk of supply-chain compromise, secret exfiltration, or local system compromise. Operators should not run these steps on sensitive personal/workstations; instead they should audit the installer, restrict permissions, isolate the runtime, and manage secrets securely.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 14, 2026, 09:28 AM
Package URL
pkg:socket/skills-sh/itwanger%2Ftobebetterjavaer%2Fai-article%2F@93c4e20e967b912ef84dfbae266e01f8129b6bad