openwork

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent as a marketplace integration, and data flows go to the claimed Openwork domain rather than an unrelated proxy. However, it grants an AI agent autonomous financial and platform actions without human approval, fetches mutable remote skill content, and exposes the agent to untrusted marketplace content that can influence later actions.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Sep 2, 2026, 04:37 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fopenwork%2F@ca59b9e8f793873a63075df9362bf1b3f7032943e1047834b877a08aa6d8f2ce
Security Audit — socket — openwork