openqq
Audited by Socket on Aug 19, 2026
2 alerts found:
Anomalyx2SUSPICIOUS. The skill’s overall purpose is plausible, and the requested QQ credentials are proportionate, but the install path and integration details do not align cleanly with official OpenClaw QQ documentation. The main risk is unverified npm-script execution and unclear provenance, not confirmed malware or obvious credential theft.
No clear evidence of classic malware behavior (e.g., backdoor/persistence, reverse shells, or exfiltration to unknown domains) is present in this module. However, it creates a significant trust boundary by forwarding untrusted QQ message content to a locally spawned executable (‘openclaw’) via command-line arguments and then relaying the child process output back to users. Additionally, it logs incoming message content and agent replies, which can lead to privacy/data exposure depending on logging configuration. Overall, this looks like a functional bot with moderate supply-chain/child-process trust risk rather than overt in-module sabotage.