openclaw-nerve-cockpit

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated OpenClaw cockpit purpose, but its footprint is high-impact: remote installer execution from a personal GitHub repo, broad workspace/control access, optional credential injection, and network-exposed admin modes. This looks more like a powerful but risky operations skill than confirmed malware.

Confidence: 83%Severity: 68%
Audit Metadata
Analyzed At
Sep 12, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fhermes-skills%2Fopenclaw-nerve-cockpit%2F@c7c2ec98cdcdd99c744611aac71c6200d92d512562c25ff871af0eb01ad0c1e0
Security Audit — socket — openclaw-nerve-cockpit