hiclaw-collaborative-agent-os
Warn
Audited by Socket on Jun 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly consistent with deploying HiClaw, but it carries meaningful security risk due to remote-script installation, extensive credential injection into a complex agent platform, transitive loading of community skills, and examples that weaken transport security. The behavior fits the stated purpose, so this is not confirmed malware, but the footprint is high-trust and should be treated as a medium/high-risk infrastructure skill.
Confidence: 80%Severity: 68%
Audit Metadata