auto-updater-3

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The stated purpose is coherent, but the skill’s footprint is not proportionate to trusted distribution norms: it requires an unverifiable external utility from a personal GitHub release or a glot.io snippet, then uses it to enable autonomous daily updates and transitive skill changes. This is high supply-chain risk even without confirmed malicious payloads.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:26 PM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fauto-updater-3%2F@1d45d3da80a4d992e747c44f5d869bae35288f04
Security Audit — socket — auto-updater-3