openclaw-config
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s actual footprint is much broader than its stated config-management purpose. Its local file access is plausible for troubleshooting, but the inclusion of approval-bypassing agent execution, autonomous messaging/voice workflows, and third-party/transitive skill installation makes the scope disproportionate and raises meaningful security risk even without confirmed exfiltration.
Confidence: 90%Severity: 74%
Audit Metadata