openclaw-chinese-ai-assistant
Warn
Audited by Socket on May 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The overall purpose is plausible, but the skill's trust chain is inconsistent and it directs credentials and model traffic through an unofficial third-party endpoint (gpt.qt.cool). Combined with mixed publisher identities, daemonized network services, remote dashboard exposure, and transitive skill installation, the footprint is broader and riskier than a simple localization/setup guide.
Confidence: 84%Severity: 76%
Audit Metadata