desktop-sandbox

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The core flow is installer orchestration for a desktop sandbox via an external binary from GitHub releases. While the intent is legitimate, the setup carries supply-chain risk due to lack of integrity checks and potential for unattended installs. An improved report should emphasize verification, clear install paths, user consent, and isolation of downloaded payloads. Recommend adding checksum/signature verification, pinned TLS, explicit install directories, and post-install integrity checks.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:53 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fdesktop-sandbox%2F@b2c3a2f7711f956b28e535f569f709a30e9f1421
Security Audit — socket — desktop-sandbox