openclaw-config

Warn

Audited by Socket on May 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the runbook is partly legitimate for OpenClaw operations, but its actual scope is much broader than 'manage configuration'. It combines sensitive credential/file access, autonomous messaging/calling behavior, and transitive skill installation, creating a high operational security risk without clear guardrails. No confirmed malware or covert exfiltration is present.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
May 2, 2026, 12:56 PM
Package URL
pkg:socket/skills-sh/twodogegg%2Fopenclaw-doc-skills%2Fopenclaw-config%2F@e9541e60da32b49a4870139f767a2f27be3ffae4