self-improving-agent

Warn

Audited by Socket on Apr 18, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
skills/extract/SKILL.md

SUSPICIOUS. The core behavior is mostly aligned with the stated purpose of turning local patterns into reusable skills, and there is no direct credential harvesting or remote payload execution. However, the skill relies on an unverified delegated agent and references transitive install/publish commands without clear provenance, so the trust boundary extends beyond what is documented.

Confidence: 84%Severity: 52%
AnomalyLOW
hooks/hooks.json

The configuration itself is small and not overtly malicious, but it instructs automatic execution of a package-supplied shell script (./hooks/error-capture.sh) which can perform any action available to the invoking user. This is a medium-to-high supply-chain risk until the referenced script is reviewed and its behavior validated. Treat the hook as potentially dangerous: do not allow it to run in sensitive environments without inspection or sandboxing.

Confidence: 75%Severity: 60%
Audit Metadata
Analyzed At
Apr 18, 2026, 10:47 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fself-improving-agent%2F@4ed13d1885df05608e71440c43399053700dd871
Security Audit — socket — self-improving-agent