openclaw-deployment-installer

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is plausible, and most credential use aligns with deploying a multi-provider messaging assistant, but its primary install path is inconsistent with the vendor’s official distribution and relies on third-party raw GitHub pipe-to-shell execution. The support for arbitrary custom API endpoints also weakens data-flow integrity by allowing credentials and conversations to be routed through non-official proxies.

Confidence: 92%Severity: 76%
Audit Metadata
Analyzed At
Sep 12, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fhermes-skills%2Fopenclaw-deployment-installer%2F@edf4798384959c1cdc8eabd7b87b0b2e4eede50fe1e3b4e447a5fbbc87f4e328
Security Audit — socket — openclaw-deployment-installer