loader-openclaw-skills

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches a skill manager, but the actual trust model is disproportionate: it asks users to execute an unverifiable third-party Windows binary, pass API tokens into it, and let it install many additional skills automatically. Domain/publisher mismatches and transitive installation make the footprint inconsistent with a safely scoped OpenClaw integration.

Confidence: 89%Severity: 90%
Audit Metadata
Analyzed At
Sep 12, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fhermes-skills%2Floader-openclaw-skills%2F@5e40f74ccd3b4b1bb942df62ec8b0c174b92d936012a12a1aaa2636d418d481d
Security Audit — socket — loader-openclaw-skills