self-improvement
Warn
Audited by Socket on Jun 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core behavior—logging learnings to local markdown and promoting them into agent context files—is coherent and mostly proportionate to the stated purpose. The main concerns are medium supply-chain trust from installing via a registry or personal GitHub repo without pinning/verifiable releases, optional hook-based shell execution, and broader OpenClaw cross-session capabilities. No direct credential harvesting, known exfiltration endpoints, or confirmed malicious behavior are shown.
Confidence: 84%Severity: 56%
Audit Metadata