0x0-messenger

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment is coherent with a legitimate peer-to-peer messaging tool concept, aligning its stated purpose with the described capabilities (PIN-based identity, disposable numbers, QR/URI workflows, CLI and browser/mobile interfaces). There are no explicit malicious actions or credentials requested in the fragment. However, the lack of concrete implementation details about transport security, key management, and the privacy model introduces uncertainty about real-world security guarantees. Given the static nature of the fragment, it is at least suspicious enough to warrant careful review of the actual implementation for end-to-end encryption, secure PIN handling, and safe local/LAN exposure when the web UI is used.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 10:08 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2F0x0-messenger%2F@59144c3ee1d3426dee622288735f4c534646973e