openclaw-config

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s actual footprint is much broader than its stated config-management purpose. Its local file access is plausible for troubleshooting, but the inclusion of approval-bypassing agent execution, autonomous messaging/voice workflows, and third-party/transitive skill installation makes the scope disproportionate and raises meaningful security risk even without confirmed exfiltration.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Sep 12, 2026, 08:38 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Ftrending-skills%2Fopenclaw-config%2F@fb4b44d86794f8b93dcf1e190148acb8a2d9918fc74da7df6b31eb512d0045ff
Security Audit — socket — openclaw-config