security-audit-2

Fail

Audited by Socket on Mar 5, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Based on the provided manifest and README-level files, this project appears to be a defensive, fail-closed auditing tool whose declared behavior (trufflehog + semgrep + custom checks) aligns with its purpose. No direct evidence of obfuscation, hard-coded credentials, backdoors, or exfiltration is visible in the supplied fragment. The principal risks are supply-chain exposure from installing third-party tooling and the unknown contents of the referenced scripts (which were not provided). Before trusting or running the auditor: review the three referenced scripts for network calls, dynamic execution, or credential harvesting; run the audit in an isolated sandbox; and install external tools from pinned, verified sources.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 5, 2026, 07:22 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fsecurity-audit-2%2F@57f0b71e74dd5bdb7d93c982411f886a8020f822