secure-openclaw-ai-assistant

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches its capabilities, but its footprint is disproportionate for a messaging assistant. It combines full local tool access, persistent memory, remote deployment, public messaging ingress, 500+ external app actions, and multiple pipe-to-shell installers from different vendors. The main concern is high security risk from supply-chain trust and autonomous real-world integrations rather than confirmed malware or hidden exfiltration.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Sep 12, 2026, 06:52 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fhermes-skills%2Fsecure-openclaw-ai-assistant%2F@414ec60810f92a64752aeae7e00a2a60c372e70871597a043c01b117098f3328
Security Audit — socket — secure-openclaw-ai-assistant