3x-ui-setup

Fail

Audited by Socket on Mar 17, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s core capabilities broadly match its stated purpose of setting up and hardening a VPS-based 3x-ui VPN server, and the main external tools are same-org official GitHub sources rather than arbitrary third-party hosts. However, it has a larger-than-average operational footprint: it executes remote installer code as root, runs an unpinned release binary, performs subnet scanning, stores multiple secrets in guide files, and includes a transitive Claude Code installation path. This looks more like a high-risk infrastructure automation skill than credential theft, but its install trust and secret-handling are not low risk.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Mar 17, 2026, 10:56 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2F3x-ui-setup%2F@2e8b652fb4a6f85cc5e210512aff2b645330d142