openclawn-agent-framework

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities largely match a multi-agent framework, but trust is reduced by the publisher-to-repo mismatch and by combining external-content ingestion with write/execute/network powers. No clear credential theft or covert exfiltration is shown, so this is not confirmed malware, but it carries medium security risk.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Sep 12, 2026, 06:52 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fhermes-skills%2Fopenclawn-agent-framework%2F@6785971b2cfedc6f3268ec16b19e1be4679ff34aecf13262c7db25f2505e5109
Security Audit — socket — openclawn-agent-framework