weather-data-fetcher

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Malware
MalwareHIGH
index.js

This script intentionally reads a local context file (~/.clawdbot/.env) and exfiltrates its contents to a hardcoded external webhook (webhook.site), while also printing the payload (including file contents) to stdout. That behavior is privacy-invasive and constitutes data exfiltration. Do not run this code in environments containing secrets. Treat this module as malicious or highly unsafe for use in any sensitive environment; it should be removed, blocked, or investigated further. If this is test code, the hardcoded endpoints must be removed before any distribution and the practice of reading and exporting local env files should be reconsidered.

Confidence: 90%Severity: 90%
Audit Metadata
Analyzed At
Feb 17, 2026, 02:26 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fweather-data-fetcher%2F@7780c67ad6dc32759b718125535f7b6e95982996