prototype-openclaw-tui

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/launch-tmux-grid.sh

No clear supply-chain malware indicators (no obfuscation, no hardcoded secrets, no exfiltration/persistence, no network activity). However, the script intentionally executes arbitrary shell commands provided via pane_commands[] by routing them into /bin/sh -c inside tmux panes, making it a high-impact command-execution tool if inputs are attacker-controlled. macOS additionally creates and opens a temporary executable attach.command for local terminal attachment, which is execution-adjacent but appears intended solely to run tmux attach-session.

Confidence: 74%Severity: 58%
Audit Metadata
Analyzed At
Jul 31, 2026, 07:16 PM
Package URL
pkg:socket/skills-sh/steipete%2Fclawdis%2Fprototype-openclaw-tui%2F@4fc39be5bf36273370978e87c9fc4b49d8c3c4e98f4c0e1be5b2fd1e2ff1c271
Security Audit — socket — prototype-openclaw-tui