migrate-nanoclaw
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
AnomalyAnomalydiagnostics.md
LOWAnomalyLOW
diagnostics.md
This fragment is primarily a telemetry/analytics mechanism: it collects local environment and migration-related metadata (including an identifier) and, upon consent, exfiltrates that data to a third-party analytics endpoint using a hardcoded API key. While it does not show overt malware behaviors, the embedded credential and explicit third-party upload of host/runtime context create a meaningful privacy and supply-chain security risk that should be reviewed and ideally made strongly opt-in with minimal data and no embedded secrets.
Confidence: 74%Severity: 66%
Audit Metadata