capability-evolver

Fail

Audited by Socket on Mar 19, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The core behavior—autonomous self-evolution via log/history analysis followed by immediate code or memory changes—is high-risk and disproportionate for a general skill, even if openly described. Install provenance is partly coherent, but the npm naming mismatch and unpinned update paths add supply-chain uncertainty. Main concern is autonomous self-modification and continuous operation, not confirmed malware.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Mar 19, 2026, 10:47 AM
Package URL
pkg:socket/skills-sh/kirkluokun%2Fawesome-a-stock-openclawskills%2Fcapability-evolver%2F@031429af28cf4451ef88b2c965d86f55e79f4d02