migrate-from-openclaw

Warn

Audited by Socket on Aug 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s behavior is mostly coherent with a migration assistant: it reads old local state, maps it into NanoClaw, and stores credentials in plausible local destinations. The main risk is breadth: it accesses raw secrets from local files, executes many local project/service commands, and can import old skills/MCP configurations into the new environment. I see no strong sign of credential harvesting or off-platform exfiltration, so this is not malware, but it is a medium-risk skill that should only be used with careful user review of imported credentials, skills, and plugins.

Confidence: 87%Severity: 57%
Audit Metadata
Analyzed At
Aug 30, 2026, 02:01 AM
Package URL
pkg:socket/skills-sh/nanocoai%2Fnanoclaw%2Fmigrate-from-openclaw%2F@b58247cf687123f4b17d6d6748b94ab0c4ebb3d6a7e3a18845d321d9f6e5978b
Security Audit — socket — migrate-from-openclaw