openclaw-bot-review-dashboard

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly coherent with a local OpenClaw monitoring dashboard, and its network flows target official/local endpoints rather than obvious exfiltration services. However, trust is weakened by the mismatch between the stated publisher and the GitHub repo owner, and the app reads secret-bearing OpenClaw config while mounting the full OpenClaw directory into the runtime. This looks more like a moderately risky admin dashboard than malware.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
May 17, 2026, 04:23 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fopenclaw-bot-review-dashboard%2F@b292a3dfcb6e50c57c6fc5e4c5d870650768ca26
Security Audit — socket — openclaw-bot-review-dashboard