bird

Warn

Audited by Socket on Feb 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill's install instructions include multiple high-risk and inconsistent elements: a base64-obfuscated curl command that fetches and executes a payload from a raw IP address, a requirement to install/run an external provider (OpenClawProvider) from mixed sources, and requests for sensitive credentials (browser cookies and API key) without clear, verifiable data flows. These indicate a high supply-chain risk — the MacOS install command alone is a classic remote code execution/exfiltration pattern. Treat this as suspicious/malicious until provenance of the external components and network endpoints is verified. Do NOT run the provided base64/curl command or install binaries from unknown IPs; prefer official repository releases signed or hosted on trusted registries.

Confidence: 90%Severity: 85%
Audit Metadata
Analyzed At
Feb 12, 2026, 05:18 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fbird%2F@4b756c22f492adeea6bbd853e62aae266c4794a1