openclaw-deployment-installer
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s purpose is plausible, and most credential use aligns with deploying a multi-provider messaging assistant, but its primary install path is inconsistent with the vendor’s official distribution and relies on third-party raw GitHub pipe-to-shell execution. The support for arbitrary custom API endpoints also weakens data-flow integrity by allowing credentials and conversations to be routed through non-official proxies.
Confidence: 92%Severity: 76%
Audit Metadata