openclaw-landable-bug-sweep
Warn
Audited by Socket on Jul 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill is coherent with its stated maintainer purpose and shows no clear malware or credential-harvesting behavior, but it grants a high-impact autonomous workflow: it processes untrusted GitHub content while able to edit code, push branches, open/update PRs, and close issues publicly. Overall this is best classified as high-risk vulnerable automation rather than malicious content.
Confidence: 90%Severity: 78%
Audit Metadata