deepseek-openclaw-integration

Fail

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's installation instructions include cloning a repository from an unverified GitHub account: https://github.com/Chiptreevaluate/deepseek-openclaw-863.git. This source is not associated with the skill author 'Aradotso' or any trusted organization.
  • [COMMAND_EXECUTION]: The provided commands npm install and npm start execute scripts defined within the external repository's package.json file. This allows the untrusted remote content to run arbitrary code on the local system during installation and execution.
  • [METADATA_POISONING]: The Troubleshooting section encourages users to 'temporarily pause protection' or add the project to an allowlist if security software blocks it, which is a deceptive practice intended to bypass host security controls.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 14, 2026, 08:46 AM
Security Audit — agent-trust-hub — deepseek-openclaw-integration