openclaw

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aims to manage OpenClaw registry interactions for searching and installing skills, which inherently involves executing code from a remote registry and performing transitive installations. While the described workflow is plausible for a registry-backed skill manager, it introduces non-trivial security risks: remote code execution during installation, reliance on an unverified external registry, and automatic integration of newly installed skills into the agent’s prompts without per-skill user consent. These patterns are inconsistent with a tightly-scoped, low-risk skill. Treat as SUSPICIOUS to HIGH-RISK (securityRisk ~0.6) until mitigations are in place (e.g., pinned registry sources, code-signing, per-skill review, explicit user approval before loading new skills).

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 07:36 AM
Package URL
pkg:socket/skills-sh/ZHangZHengEric%2FSage%2Fopenclaw%2F@592da2a0f040f8ec54a05b686b872eed8ab4efd0