openclaw-mission-control

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s documented capabilities largely fit its stated purpose, and most flagged patterns are normal documentation examples. The main concern is install trust: a pipe-to-shell installer from a mutable raw GitHub URL under a different owner than the named publisher creates a meaningful supply-chain risk. Credential use appears proportionate for a self-hosted orchestration platform, and documented data flows stay mainly between the user, local API, and configured gateways rather than obvious third-party exfiltration endpoints.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Sep 12, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fhermes-skills%2Fopenclaw-mission-control%2F@cd0e510503afd01ca5344876d2151c52c39e1e4297e928f4bcf2a6ad144ac04c
Security Audit — socket — openclaw-mission-control