zeroclaw

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is broadly consistent with its stated purpose as an autonomous AI infrastructure guide, so it does not show clear malicious misalignment. However, it enables a high-risk runtime: persistent background service, multi-channel control, provider credential use, arbitrary custom endpoints, and a documented no-approval autonomy mode. Overall this looks purpose-aligned but security-sensitive rather than benign-by-default.

Confidence: 82%Severity: 76%
Audit Metadata
Analyzed At
Mar 16, 2026, 10:52 PM
Package URL
pkg:socket/skills-sh/Perseusmx%2Fzeroclaw-skill%2Fzeroclaw%2F@f52def9981305d373c6a30baf61824113ac01fb7