openclaw-deployment-installer
Warn
Audited by Socket on May 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the overall purpose is plausible, but the trust story is weak. The skill uses unpinned remote shell installers from an unrelated GitHub org, handles many credentials, and explicitly allows routing model traffic to arbitrary custom endpoints. Those behaviors may fit OpenClaw’s functionality, but they create medium-high security risk and an integrity gap between the Hermes publisher and the installed software.
Confidence: 86%Severity: 78%
Audit Metadata