openclaw-upgrade

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/upgrade.sh

No clear evidence of intentional malware (no backdoor, exfiltration, reverse shell, or dynamic code execution) in this Bash upgrader. However, it meaningfully expands the supply-chain attack surface by performing global npm/pnpm installs/upgrades (openclaw@channel and conditional installation of `long`) without integrity pinning, and it can delete/reinstall node_modules in assumed directories and force-kill/restart processes. These are security-relevant risks and should be reviewed in the context of package provenance and registry integrity controls.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Sep 4, 2026, 06:58 AM
Package URL
pkg:socket/skills-sh/delorenj%2Fskills%2Fopenclaw-upgrade%2F@36cea19029121e8f75175ec1d6f50611baeaf630da4ff239b6215e43eb294a6c
Security Audit — socket — openclaw-upgrade