alibabacloud-openclaw-ecs-dingtalk

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core deployment purpose is coherent, but the skill’s trust model is weak: it auto-creates a cloud API key, collects DingTalk secrets, and forwards both into cloud-executed shell commands that download and run unpinned remote scripts. This is a high security risk supply-chain and credential-handling pattern, even without proof of confirmed malware.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Apr 11, 2026, 12:44 PM
Package URL
pkg:socket/skills-sh/aliyun%2Falibabacloud-aiops-skills%2Falibabacloud-openclaw-ecs-dingtalk%2F@19faf2d6f401c67b019b413e941e1c583214aad4