iblai-api-infrastructure

Warn

Audited by Socket on Jul 27, 2026

1 alert found:

Security
SecurityMEDIUM
references/claw-servers.md

No direct evidence of malware/backdoor logic is present in the provided fragment (it is a deployment runbook). However, it exhibits multiple high-risk supply-chain and credential-handling practices: executing remote installer scripts via curl|bash, installing OpenClaw from an unpinned openclaw@latest version, and persisting sensitive tokens/API keys into ~/.bashrc. The dominant threat is upstream/registry/installer compromise and credential leakage rather than malicious behavior explicitly implemented in this snippet.

Confidence: 64%Severity: 72%
Audit Metadata
Analyzed At
Jul 27, 2026, 11:41 AM
Package URL
pkg:socket/skills-sh/iblai%2Fapi%2Fiblai-api-infrastructure%2F@4e5900f49fbe366dbfca3f704f845811a11d53f847ed88a28e08b86d67e8da0a
Security Audit — socket — iblai-api-infrastructure