openclaw-mission-control
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s documented capabilities largely fit its stated purpose, and most flagged patterns are normal documentation examples. The main concern is install trust: a pipe-to-shell installer from a mutable raw GitHub URL under a different owner than the named publisher creates a meaningful supply-chain risk. Credential use appears proportionate for a self-hosted orchestration platform, and documented data flows stay mainly between the user, local API, and configured gateways rather than obvious third-party exfiltration endpoints.
Confidence: 89%Severity: 68%
Audit Metadata