oauth-helper

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose matches browser OAuth automation, but its footprint is high-risk: it uses pre-logged identity-provider sessions, can authorize third-party site access, and routes sensitive auth context and possibly screenshots/QR codes through Telegram. There is no clear malware payload or installer abuse, but the data flow and real-world account actions are disproportionate enough to treat it as a high-risk vulnerable skill.

Confidence: 88%Severity: 81%
Audit Metadata
Analyzed At
Sep 2, 2026, 04:33 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Foauth-helper%2F@9704d8112d5b1893058adc1b671df271b3b540206aa3afb722e62d5c6a46ab26
Security Audit — socket — oauth-helper