openclaw-admin-vue

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core admin/dashboard purpose is coherent, and most capabilities target local OpenClaw/Hermes management. However, the skill materially increases trust risk through an unpinned raw GitHub pipe-to-shell Hermes installer and support for arbitrary GitHub-based skill installation, while also handling API keys through Hermes; this is more than low-risk documentation but not confirmed malicious.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Sep 12, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fhermes-skills%2Fopenclaw-admin-vue%2F@d6cbd46a0f19492167440dc9d3db6ed377b1b1d1f4ba269d27ed32c41258bef6
Security Audit — socket — openclaw-admin-vue