openqq

Warn

Audited by Socket on Aug 19, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is plausible, and the requested QQ credentials are proportionate, but the install path and integration details do not align cleanly with official OpenClaw QQ documentation. The main risk is unverified npm-script execution and unclear provenance, not confirmed malware or obvious credential theft.

Confidence: 84%Severity: 61%
AnomalyLOW
qq-bot.js

No clear evidence of classic malware behavior (e.g., backdoor/persistence, reverse shells, or exfiltration to unknown domains) is present in this module. However, it creates a significant trust boundary by forwarding untrusted QQ message content to a locally spawned executable (‘openclaw’) via command-line arguments and then relaying the child process output back to users. Additionally, it logs incoming message content and agent replies, which can lead to privacy/data exposure depending on logging configuration. Overall, this looks like a functional bot with moderate supply-chain/child-process trust risk rather than overt in-module sabotage.

Confidence: 62%Severity: 52%
Audit Metadata
Analyzed At
Aug 19, 2026, 07:48 PM
Package URL
pkg:socket/skills-sh/bighardperson%2Fcomputer-science-skills-collection%2Fopenqq%2F@331e94af028246b19e7e1f8ec844a442ccaffed3b47934970a283f1234c2bb20
Security Audit — socket — openqq