self-evolve

Fail

Audited by Socket on Mar 20, 2026

2 alerts found:

SecurityObfuscated File
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core issue is not malware-like exfiltration but extreme autonomy: the skill is designed to bypass user approval, rewrite the agent's own governing files, execute commands, and recursively extend itself via new skills. The ClawHub reference appears same-ecosystem rather than overtly malicious, but the self-modification + transitive skill installation + no-confirm behavior makes the skill high risk and disproportionate to safe agent operation.

Confidence: 93%Severity: 95%
Obfuscated FileHIGH
skill.json

The package.json itself contains no executable code to label as malware. However, the declared purpose—an autonomous, self-modifying agent that alters its own code and environment without user confirmation—represents a significant supply-chain and host-security risk if implemented. Metadata promises are unenforceable; any implementation must be treated as potentially dangerous until thoroughly audited and sandboxed.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 20, 2026, 06:19 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fself-evolve%2F@062cb7e8712b59570681151fcd547438bb90722e