mission-control

Warn

Audited by Socket on Apr 8, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
assets/index.html

No direct, explicit malware (e.g., crypto-mining, reverse shell, keylogging) is evident in this snippet. However, it has a high security risk due to multiple DOM XSS sinks (innerHTML/template-literal rendering of task fields and GitHub-provided content without escaping) combined with storing a GitHub PAT in localStorage. Successful XSS would likely enable token theft and unauthorized repository modification. Additionally, the code includes a gateway-based cron execution trigger, which is high-impact if an attacker can influence gatewayUrl or cron-related data.

Confidence: 70%Severity: 82%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is largely coherent for task orchestration, but it materially expands the agent from tracking tasks into autonomous execution triggered by webhooks and status changes. Credential needs and network flows are mostly purpose-aligned, yet the auto-run behavior, broad repo access, and weaker publisher/install trust make this a high-risk workflow skill rather than a benign dashboard-only tool.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Apr 8, 2026, 02:46 PM
Package URL
pkg:socket/skills-sh/g-hunterai%2Fopenclaw-skills%2Fmission-control%2F@171c76e62510562dd32e4ae8a4afa104c914ab21
Security Audit — socket — mission-control