ai-web-automation-hardened
Audited by Socket on Apr 21, 2026
2 alerts found:
AnomalyObfuscated FileSUSPICIOUS. The skill is broadly consistent with web automation, and the OpenClaw CLI appears to come from an official same-org source, so this is not confirmed malware. However, the undocumented-looking command path, proxy-pool feature, outbound notification paths, and autonomous scheduled web actions make the skill higher risk than a normal documentation-only skill.
The provided artifact is a defensive guardrail and safety-policy document. It does not contain executable malware or active data flows. Its security posture depends on faithful enforcement of guardrails in the production implementation. When properly enforced, risk remains medium-low due to explicit prohibitions and safe alternatives; risk escalates if guardrails are misconfigured or bypassed, enabling data exposure or unauthorized scraping.