deepseek-openclaw-config-generator

Warn

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to clone a source code repository from an unverified GitHub account (https://github.com/LawmakerTreasure/deepseek-openclaw.git). This source is not associated with a trusted organization or the skill's listed author ('Aradotso').
  • [COMMAND_EXECUTION]: The documentation encourages users to execute local shell commands such as npm install and npm run dev within the cloned repository. This involves running untrusted scripts and dependencies on the user's machine, which could facilitate the execution of malicious code.
  • [REMOTE_CODE_EXECUTION]: The combined pattern of fetching unverified code from an external source and executing build/startup scripts creates a remote code execution risk, as the integrity and safety of the repository's contents are not guaranteed.
  • [EXTERNAL_DOWNLOADS]: The model catalog in the skill references "DeepSeek V4" models, which are not currently available or announced by the official provider. The use of deceptive or non-existent technical specifications to lure users into downloading external software is a suspicious behavior that elevates the risk of the untrusted repository.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 14, 2026, 08:47 AM
Security Audit — agent-trust-hub — deepseek-openclaw-config-generator