metaclaw-evolving-agent
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's interception, storage, and training behavior fits its stated purpose, but the trust story does not: publisher identity is inconsistent across ara.so, aiming-lab, and PyPI sources, and the skill asks for multiple high-value credentials while proxying all conversations to external backends. The main concern is supply-chain and provenance ambiguity rather than confirmed malware.
Confidence: 90%Severity: 78%
Audit Metadata