dingtalk-openclaw-connector

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly purpose-aligned for a DingTalk connector, but it gives an agent broad enterprise write/action powers and forwards DingTalk credentials to an external package whose publisher ownership is not verified in the provided material. This looks more like a high-risk integration than confirmed malware.

Confidence: 79%Severity: 58%
Audit Metadata
Analyzed At
May 17, 2026, 05:25 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fdingtalk-openclaw-connector%2F@161124534982a7e5196ed758936a5c571ce286ec
Security Audit — socket — dingtalk-openclaw-connector