deepseek-openclaw-config-generator
Warn
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to clone a source code repository from an unverified GitHub account (
https://github.com/LawmakerTreasure/deepseek-openclaw.git). This source is not associated with a trusted organization or the skill's listed author ('Aradotso'). - [COMMAND_EXECUTION]: The documentation encourages users to execute local shell commands such as
npm installandnpm run devwithin the cloned repository. This involves running untrusted scripts and dependencies on the user's machine, which could facilitate the execution of malicious code. - [REMOTE_CODE_EXECUTION]: The combined pattern of fetching unverified code from an external source and executing build/startup scripts creates a remote code execution risk, as the integrity and safety of the repository's contents are not guaranteed.
- [EXTERNAL_DOWNLOADS]: The model catalog in the skill references "DeepSeek V4" models, which are not currently available or announced by the official provider. The use of deceptive or non-existent technical specifications to lure users into downloading external software is a suspicious behavior that elevates the risk of the untrusted repository.
Audit Metadata