openclaw-autonomous-issue-sweep

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s capabilities broadly match a repository maintainer automation role, but its footprint is high risk because it combines large-scale autonomous GitHub mutations, local/remote command execution, and ingestion of untrusted GitHub content. The install/tooling evidence is mostly same-org or official, so the main concern is not malware or deceptive supply chain behavior but unsafe autonomy and prompt-injection exposure.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Jul 31, 2026, 07:16 PM
Package URL
pkg:socket/skills-sh/steipete%2Fclawdis%2Fopenclaw-autonomous-issue-sweep%2F@3c56407b4c877d70e4c92a69e167577b3a9be02e0655372df3dcbbd3a0d68110
Security Audit — socket — openclaw-autonomous-issue-sweep