brain

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the Brain skill is largely coherent with its stated purpose as a personal knowledge base and retrieval system. The main security consideration is the optional external QMD backend installation via bun from a GitHub URL, which constitutes an unverifiable binary supply-chain risk. If users enable this backend, securityRisk should be elevated accordingly. Otherwise, the footprint remains benign and proportionate to the described functionality.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 07:31 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fbrain%2F@27e29ea846ef8aba55c2f9fa41def7370c0ea51b