openclaw-installer-deployment

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose broadly matches its capabilities, but the install and configuration path is not well aligned with OpenClaw’s official distribution: it routes users to a third-party GitHub installer repo, uses multiple mutable curl|bash commands, and requests numerous sensitive API and bot credentials for a service with remote-control abilities. I see no confirmed malware or explicit exfiltration endpoint, but the supply-chain trust and credential-handling footprint are too broad to treat as benign.

Confidence: 91%Severity: 76%
Audit Metadata
Analyzed At
Sep 12, 2026, 06:52 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fhermes-skills%2Fopenclaw-installer-deployment%2F@c401bd53701e8dd7d636e702bb1ff8b7a2493be24803a1444ce0417c48f6a731
Security Audit — socket — openclaw-installer-deployment