openclaw-landable-bug-sweep

Warn

Audited by Socket on Jul 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is coherent with its stated maintainer purpose and shows no clear malware or credential-harvesting behavior, but it grants a high-impact autonomous workflow: it processes untrusted GitHub content while able to edit code, push branches, open/update PRs, and close issues publicly. Overall this is best classified as high-risk vulnerable automation rather than malicious content.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Jul 9, 2026, 07:24 PM
Package URL
pkg:socket/skills-sh/steipete%2Fclawdis%2Fopenclaw-landable-bug-sweep%2F@e3d4d6cdcdb6beed77920560971c8a1fc3563e9299881b47d43ec44b768e43e3
Security Audit — socket — openclaw-landable-bug-sweep