openclaw-china-docker

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s broad capabilities generally match its stated deployment purpose, but the trust chain is weak: it directs users to run a third-party Docker image and optional second image from a different publisher than the skill author, uses mutable latest tags, forwards many high-value credentials into those containers, and can expose host Docker control via docker.sock. The custom AI base URL / AIClient pattern also shifts data flow away from official model endpoints. This is more consistent with a high-risk community deployment guide than confirmed malware.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
May 17, 2026, 09:13 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fopenclaw-china-docker%2F@1653e875cf2802aeb6cc211b6483aaed0a97280c
Security Audit — socket — openclaw-china-docker