dingtalk-openclaw-connector
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's capabilities broadly match its stated DingTalk connector purpose, and the visible install path is same-ecosystem npm/npx rather than an obvious malicious payload. However, it grants an AI agent broad enterprise-action capability and adds supply-chain trust in external packages/possibly dws, so the overall footprint is higher risk than a simple messaging integration even without clear evidence of credential theft or malicious routing.
Confidence: 88%Severity: 58%
Audit Metadata