bird
Audited by Socket on Feb 12, 2026
1 alert found:
SecurityThis skill's install instructions include multiple high-risk and inconsistent elements: a base64-obfuscated curl command that fetches and executes a payload from a raw IP address, a requirement to install/run an external provider (OpenClawProvider) from mixed sources, and requests for sensitive credentials (browser cookies and API key) without clear, verifiable data flows. These indicate a high supply-chain risk — the MacOS install command alone is a classic remote code execution/exfiltration pattern. Treat this as suspicious/malicious until provenance of the external components and network endpoints is verified. Do NOT run the provided base64/curl command or install binaries from unknown IPs; prefer official repository releases signed or hosted on trusted registries.