api-provider-setup

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches config editing for OpenClaw, but its actual data flow normalizes forwarding API keys and model traffic to third-party relay/proxy domains rather than official provider endpoints. The unverifiable local sync script and direct handling of cached auth files add risk, though there is no clear exploit payload or confirmed malware.

Confidence: 91%Severity: 83%
Audit Metadata
Analyzed At
Apr 27, 2026, 05:15 PM
Package URL
pkg:socket/skills-sh/aaaaqwq%2Fagi-super-skills%2Fapi-provider-setup%2F@c23f4388d7b6df7300dc7525c5caa4dc3591ebaa
Security Audit — socket — api-provider-setup