openclaw-security-monitor
Fail
Audited by Socket on May 11, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
SUSPICIOUS. The skill's monitoring and remediation features broadly match its stated security purpose, but its trust model is weak: it is distributed from a personal GitHub repo, executes multiple shell scripts, reads highly sensitive local paths, and can make sweeping system changes with optional auto-approval and persistence. I see no clear evidence of deliberate credential theft or covert exfiltration, so this is not confirmed malware, but it is high-risk and should only be used after independent review of the repo contents.
Confidence: 82%Severity: 78%
Audit Metadata