ai-web-automation-hardened

Fail

Audited by Socket on Apr 21, 2026

2 alerts found:

AnomalyObfuscated File
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly consistent with web automation, and the OpenClaw CLI appears to come from an official same-org source, so this is not confirmed malware. However, the undocumented-looking command path, proxy-pool feature, outbound notification paths, and autonomous scheduled web actions make the skill higher risk than a normal documentation-only skill.

Confidence: 83%Severity: 58%
Obfuscated FileHIGH
SAFETY.md

The provided artifact is a defensive guardrail and safety-policy document. It does not contain executable malware or active data flows. Its security posture depends on faithful enforcement of guardrails in the production implementation. When properly enforced, risk remains medium-low due to explicit prohibitions and safe alternatives; risk escalates if guardrails are misconfigured or bypassed, enabling data exposure or unauthorized scraping.

Confidence: 92%
Audit Metadata
Analyzed At
Apr 21, 2026, 06:33 PM
Package URL
pkg:socket/skills-sh/faberlens%2Fhardened-skills%2Fai-web-automation-hardened%2F@9d8fb17206a294bc471103b43d1e665e2ca82cde
Security Audit — socket — ai-web-automation-hardened