openclaw
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core setup purpose is plausible, but the skill’s footprint is broader than a simple config installer. The biggest concerns are unverifiable install provenance, an autonomous hourly Claude cron job, and use of --dangerously-skip-permissions. Optional API integrations are mostly proportional, but combined with autonomous workflows they materially raise risk.
Confidence: 86%Severity: 81%
Audit Metadata