openclaw-mem

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/setup.sh

This is a thin installer/initializer wrapper that immediately installs and then executes a third-party package via pip. The fragment itself shows no overt malicious logic, but it creates a significant dependency supply-chain risk by using an unpinned, unverified pip install followed by direct execution (`openclaw-mem init`) without validation. Malware cannot be confirmed from this snippet alone; risk hinges on the actual package contents and pip configuration (index/provenance).

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 08:06 AM
Package URL
pkg:socket/skills-sh/kjaylee%2Fmisskim-skills%2Fopenclaw-mem%2F@992fa9ef8214aa1d25e668240c6804558459f611