openclaw-config

Fail

Audited by Socket on Mar 5, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The combined fragment provides a practical, multi-path OpenClaw configuration and installation workflow, which is useful for legitimate setup across platforms. However, the prevalent use of remote install scripts (curl|bash, iwr|iex) without explicit integrity verification and the presence of environment-based credential references introduce non-trivial supply-chain and secret-exposure risks. To reduce risk, adopt signed/artifact-based installers, pin versions with hash checks, minimize on-device credential exposure, and implement explicit secret-management practices (directed through secure vaults or managed envs) with tighter control over config includes. Treat the artifact as SUSPICIOUS with high caution for production use, and prefer auditable, verifiable installers and documented security checks.

Confidence: 92%
Audit Metadata
Analyzed At
Mar 5, 2026, 02:23 AM
Package URL
pkg:socket/skills-sh/pc-style%2Fskills%2Fopenclaw-config%2F@974b17ccc88ba703038888e11fc57f0027870a3e