swarm-self-heal

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/check.sh

This snippet is not malicious by itself; it is a launcher that unconditionally executes `anvil_watchdog.sh` from `~/.openclaw/...` without integrity verification. The main concern is execution/integrity risk: if that user-local script is tampered with or replaced, the launcher will run the attacker’s code. Inspect `anvil_watchdog.sh` and verify how that file is installed/upgraded and whether its integrity is protected.

Confidence: 62%Severity: 56%
Audit Metadata
Analyzed At
Mar 27, 2026, 02:07 PM
Package URL
pkg:socket/skills-sh/cacheforge-ai%2Fcacheforge-skills%2Fswarm-self-heal%2F@a2bdb2b28eccd7ad210f91e57c8ffb58e0a3ee86
Security Audit — socket — swarm-self-heal