auto-updater

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill's purpose matches its behavior, but its footprint is high-risk because it automates registry-wide and agent-wide updates on a schedule without per-action approval. The main concern is supply-chain and transitive trust expansion, not confirmed malware or credential theft.

Confidence: 90%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 05:00 PM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fauto-updater%2F@d5ac515f75f262f9adfcd415cbea3fc702abe8c7