openclaw-ccc-bridge
Warn
Audited by Socket on Apr 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated bridge purpose is plausible, but its actual footprint is broader and riskier than necessary: it delegates arbitrary agent tasks to an external, not-clearly-verified `ccc` CLI, routes execution through Claude Code with `--dangerously-skip-permissions`, and expands autonomous action scope via dispatch/batch/YOLO patterns. The Anthropic npm dependency is official, but the bridge's core trust anchor is the unverifiable `ccc` binary, so overall risk is high even without direct evidence of credential theft.
Confidence: 89%Severity: 86%
Audit Metadata