certificate-generation

Warn

Audited by Socket on Feb 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Outbound data post or form upload via curl/wget detected All findings: [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] [HIGH] data_exfiltration: Outbound data post or form upload via curl/wget detected (NW002) [AITech 8.2.3] BENIGN but with moderate trust considerations: the skill is a documentation/instruction file that instructs clients to call a third-party API (sense.eachlabs.run) with an API key and prompt data to generate certificates. There is no embedded malware or download-execute behavior. Main risks are (1) trust in the external eachlabs service because user data and API key are sent there, and (2) potential misuse to generate fraudulent official-looking documents. If you plan to use this skill, ensure the eachlabs endpoint and operator are trusted, restrict which credentials you provide, and avoid sending sensitive or legally binding private keys/signature images unless you trust the service and have appropriate agreements. LLM verification: The selected report appropriately captures the external API-based certificate generation workflow, data flow, and credential handling patterns. It identifies the data leakage risk from outbound prompts and acknowledges governance needs without asserting malicious activity. Overall, the risk is moderate due to external data sharing but not indicative of malware or backdoors.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 23, 2026, 08:47 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fcertificate-generation%2F@4086ce395a7d9fe19b71c144ca649118ab987570