cross-team-comm
Warn
Audited by Socket on Aug 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This skill is not clearly malware, but it is high-risk and suspicious in scope. Its stated purpose is cross-team communication, yet it also instructs the agent to SSH into remote hosts, enumerate configs and identities, extract tokens and channel metadata, and retain them in MEMORY.md; that access is disproportionate to simple messaging even though most network flows target expected OpenClaw, SSH/Tailscale, and official Feishu endpoints.
Confidence: 87%Severity: 78%
Audit Metadata