openclaw-installer-deployment

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s broad remote-control assistant scope is partly consistent with OpenClaw’s stated purpose, but the trust model is weak: a different-party GitHub raw installer is piped to bash, then a globally installed CLI is given many API keys and bot tokens, while optional custom proxy URLs can route those credentials and user data to non-official endpoints. This is not confirmed malware, but it is a high-risk installer/deployment skill with disproportionate capability and supply-chain exposure.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
May 17, 2026, 11:28 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fopenclaw-installer-deployment%2F@a52f8a5e35f2befb472fee5821969ae8f4301dbf
Security Audit — socket — openclaw-installer-deployment