causal-inference

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated causal-planning purpose is plausible, but its actual footprint is overly broad: it triggers on almost any consequential action, backfills sensitive communication history, and relies on third-party CLIs for account access. There is no clear exfiltration or confirmed malicious payload, but the scope and credential-adjacent tooling make it higher-risk than a narrowly scoped analytics skill.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Mar 24, 2026, 12:26 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fcausal-inference%2F@71fda56c34f497775686fb99e503121554c06740