openclaw-chinese-ai-assistant

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The overall purpose is plausible, but the skill's trust chain is inconsistent and it directs credentials and model traffic through an unofficial third-party endpoint (gpt.qt.cool). Combined with mixed publisher identities, daemonized network services, remote dashboard exposure, and transitive skill installation, the footprint is broader and riskier than a simple localization/setup guide.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
May 17, 2026, 06:09 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fopenclaw-chinese-ai-assistant%2F@b1421b5910c7c896603cb9a9f14eb9d0392459b6
Security Audit — socket — openclaw-chinese-ai-assistant