openclaw-security-monitor

Fail

Audited by Socket on May 11, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill's monitoring and remediation features broadly match its stated security purpose, but its trust model is weak: it is distributed from a personal GitHub repo, executes multiple shell scripts, reads highly sensitive local paths, and can make sweeping system changes with optional auto-approval and persistence. I see no clear evidence of deliberate credential theft or covert exfiltration, so this is not confirmed malware, but it is high-risk and should only be used after independent review of the repo contents.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
May 11, 2026, 10:51 AM
Package URL
pkg:socket/skills-sh/marcoamu%2Fopenclaw-workspace%2Fopenclaw-security-monitor%2F@c644bee1d5005c95a93c4353d06bee5f5ffb88d9
Security Audit — socket — openclaw-security-monitor