update-nanoclaw

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
diagnostics.md

This code is primarily a telemetry/diagnostics component: it collects local environment and version/repository context, stages it in /tmp, and (upon consent) exfiltrates it to a third-party analytics service over HTTPS using a hardcoded API key, then deletes the staging file. No overt malware/backdoor behavior is visible, but the external transmission and embedded API key create a meaningful supply-chain privacy/security risk (device/install fingerprinting potential and non-local data egress).

Confidence: 80%Severity: 62%
Audit Metadata
Analyzed At
May 4, 2026, 07:52 PM
Package URL
pkg:socket/skills-sh/qwibitai%2Fnanoclaw%2Fupdate-nanoclaw%2F@a98b3b01b8aa9bf83b4f99810e636b50784049fb