ClawdStrike

Fail

Audited by Socket on Mar 2, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The improved assessment maintains a solid, governance-focused audit workflow for OpenClaw deployments, with explicit evidence-driven reporting. Strengths include structured use of verified-bundle.json, firewall state, and reference-driven checks. Key risk remains the automated collection step (collect_verified.sh) without per-action consent; mitigate with explicit triggers, isolation, and integrity checks. Overall, the approach is sound when executed in trusted environments with enforced consent and sandboxing.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 2, 2026, 01:56 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fclawdstrike%2F@fb8eea013ee2227269e51c6511b7211f80760246