graincrawl
Warn
Audited by Socket on May 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities generally match its archive/search purpose, but install trust is weakened by a provenance mismatch between the stated publisher (`openclaw`) and the Go module source (`vincentkoc`), plus an unpinned `@latest` external CLI. Data access appears proportionate, and there is no direct evidence of credential theft or malicious exfiltration, but the binary’s trust chain is not internally consistent enough to rate fully benign.
Confidence: 84%Severity: 64%
Audit Metadata