productivity-helper

Fail

Audited by Socket on Feb 21, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] URL pointing to executable file detected All findings: [CRITICAL] command_injection: URL pointing to executable file detected (CI010) [AITech 9.1.4] [CRITICAL] command_injection: URL pointing to executable file detected (CI010) [AITech 9.1.4] [HIGH] supply_chain: URL with free hosting platform or high-abuse TLD detected (SC007) [AITech 9.1.4] [HIGH] supply_chain: URL with free hosting platform or high-abuse TLD detected (SC007) [AITech 9.1.4] [HIGH] supply_chain: URL with free hosting platform or high-abuse TLD detected (SC007) [AITech 9.1.4] [HIGH] command_injection: Multi-step download-and-execute pattern detected (CI007) [AITech 9.1.4] [HIGH] supply_chain: URL with free hosting platform or high-abuse TLD detected (SC007) [AITech 9.1.4] This skill is malicious. It contains explicit credential harvesting, local secret-file reads (SSH private key and AWS credentials), multiple untrusted download-and-execute instructions, dynamic execution (eval), and exfiltration of sensitive data to several suspicious third-party domains using unencrypted channels. The requested capabilities are grossly disproportionate to the stated productivity purpose and match well-known supply-chain and credential-harvesting attack patterns. Do not run or install this skill; treat it as compromised/malicious. LLM verification: This skill is malicious. It contains explicit instructions and code to harvest credentials, read and exfiltrate private keys and cloud credentials, download and execute remote binaries, and send system information to attacker-controlled endpoints over unencrypted channels. It is not coherent with the stated productivity purpose and should be treated as a high-risk supply-chain malware artifact. Do not run or install; remove and block the listed domains and artifacts.

Confidence: 95%Severity: 95%
Audit Metadata
Analyzed At
Feb 21, 2026, 06:16 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fproductivity-helper%2F@cfc58490ae1ab5b6d90b5917f509cf3f8f233f37