openclaw

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is coherent with its stated purpose and uses an official install path, so it does not look malicious. However, OpenClaw’s purpose itself is high risk: it bridges untrusted external content into AI agents, stores channel tokens locally, supports webhook-triggered execution, sub-agents, and scheduled outbound messaging. This should be classified as BENIGN in intent but HIGH security risk in operation.

Confidence: 83%Severity: 79%
Audit Metadata
Analyzed At
Mar 13, 2026, 09:19 PM
Package URL
pkg:socket/skills-sh/TerminalSkills%2Fskills%2Fopenclaw%2F@851b49ce1b06b9974f1f14b0f1dc8a3eaa070215