desktop-sandbox

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The core flow is installer orchestration for a desktop sandbox via an external binary from GitHub releases. While the intent is legitimate, the setup carries supply-chain risk due to lack of integrity checks and potential for unattended installs. An improved report should emphasize verification, clear install paths, user consent, and isolation of downloaded payloads. Recommend adding checksum/signature verification, pinned TLS, explicit install directories, and post-install integrity checks.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:53 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fdesktop-sandbox%2F@b2c3a2f7711f956b28e535f569f709a30e9f1421