openclaw-windows-node
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent for a Windows companion/node controller, and its install sources are mostly official or same-project. However, its actual footprint is high-risk by design: it stores tokens locally, opens broad remote-control/data-capture capabilities, and can execute commands and exfiltrate screenshots/camera/STT results through the gateway. This looks like a legitimate but powerful remote-control skill rather than confirmed malware.
Confidence: 88%Severity: 72%
Audit Metadata