dingtalk-openclaw-connector

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly match its stated DingTalk connector purpose, and the visible install path is same-ecosystem npm/npx rather than an obvious malicious payload. However, it grants an AI agent broad enterprise-action capability and adds supply-chain trust in external packages/possibly dws, so the overall footprint is higher risk than a simple messaging integration even without clear evidence of credential theft or malicious routing.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Sep 12, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fhermes-skills%2Fdingtalk-openclaw-connector%2F@2d5a00a321f5b06b920664aa0444c9fe7550f09619e9e015abb526ccbbe938d6
Security Audit — socket — dingtalk-openclaw-connector