Cybercentry Cyber Security Consultant

Fail

Audited by Socket on Feb 21, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The fragment appears to be legitimate documentation for a paid AI security consultation service delivered via an ACP marketplace. I found no explicit malicious code, obfuscated payloads, or credential-harvesting routines in the provided text. Main risks are operational: indefinite retention of user-submitted queries (which amplifies impact of accidental secret leaks), reliance on user-side sanitization (no enforcement), unpinned npm installation instructions (standard supply-chain risk), and possible social-engineering via payment/wallet verification. Recommendations: inspect the openclaw-acp repository and package lock before npm install; add client-side sanitization/redaction tools or validation to the workflow; verify wallet addresses through independent trusted channels; avoid submitting any secrets or production identifiers in consultation queries.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 21, 2026, 06:16 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fcybercentry-cyber-security-consultant%2F@f03dbe036aa826ebe0efd710344c35627d8fc0e4