openclaw-deployment-installer

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the overall purpose is plausible, but the trust story is weak. The skill uses unpinned remote shell installers from an unrelated GitHub org, handles many credentials, and explicitly allows routing model traffic to arbitrary custom endpoints. Those behaviors may fit OpenClaw’s functionality, but they create medium-high security risk and an integrity gap between the Hermes publisher and the installed software.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
May 17, 2026, 11:52 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fopenclaw-deployment-installer%2F@213dcf242fe2fda8e4e383743ec171f1e598f338
Security Audit — socket — openclaw-deployment-installer