opendota-api

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Anomaly
AnomalyLOW
opendota.js

The code is a straightforward, read-only data collection and formatting utility for Dota 2 hero/item analyses. There is no evidence of malicious activity, backdoors, or credential handling. Primary concerns are API reliability, rate limits, and maintenance of the static item map. Overall, security posture is low-to-moderate; ensure proper handling of API errors, consider caching, and simplify or deduplicate the item map to reduce risk of inconsistencies.

Confidence: 65%Severity: 55%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:37 AM
Package URL
pkg:socket/skills-sh/seanandmengjia%2Fopenclaw-skills%2Fopendota-api%2F@e4dfcaef7f67bb3a7b3d22e236eaf623e748eac4