shadow-number

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose (acquiring disposable phone numbers and delivering OTPs) matches the described capabilities, but the design raises significant supply-chain and abuse risks. It requires a wallet credential (SHADOW_WALLET_KEY) which the agent will use to perform automated micropayments, and it routes all sensitive verification data (phone numbers and OTPs) through a third-party API hosted on railway.app. While the code is not directly executing obfuscated or self-modifying malware, these behaviors enable credential forwarding, potential fund loss, privacy violations, and explicit evasion of phone-based identity controls. If deployed to an AI agent with network and wallet permissions, this skill could be used for large-scale account creation or other abusive actions. Recommend restricting use, not providing wallet credentials to untrusted code, and avoiding routing authentication flows through unvetted third-party services.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 04:19 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fshadow-number%2F@a2d3e1a060b8020c018bef1aaa684aee3ab8b699