migrate-nanoclaw

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Anomaly
AnomalyLOW
diagnostics.md

This fragment is primarily a telemetry/analytics mechanism: it collects local environment and migration-related metadata (including an identifier) and, upon consent, exfiltrates that data to a third-party analytics endpoint using a hardcoded API key. While it does not show overt malware behaviors, the embedded credential and explicit third-party upload of host/runtime context create a meaningful privacy and supply-chain security risk that should be reviewed and ideally made strongly opt-in with minimal data and no embedded secrets.

Confidence: 74%Severity: 66%
Audit Metadata
Analyzed At
Aug 19, 2026, 07:39 AM
Package URL
pkg:socket/skills-sh/nanocoai%2Fnanoclaw%2Fmigrate-nanoclaw%2F@c17ed825f5c5d6e44ae72c7b9300c8c939e63436fe026c02b5477b1def3f4dd0
Security Audit — socket — migrate-nanoclaw