deepseek-openclaw-integration
Fail
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's installation instructions include cloning a repository from an unverified GitHub account:
https://github.com/Chiptreevaluate/deepseek-openclaw-863.git. This source is not associated with the skill author 'Aradotso' or any trusted organization. - [COMMAND_EXECUTION]: The provided commands
npm installandnpm startexecute scripts defined within the external repository'spackage.jsonfile. This allows the untrusted remote content to run arbitrary code on the local system during installation and execution. - [METADATA_POISONING]: The Troubleshooting section encourages users to 'temporarily pause protection' or add the project to an allowlist if security software blocks it, which is a deceptive practice intended to bypass host security controls.
Recommendations
- AI detected serious security threats
Audit Metadata