openclaw-backup

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS. The skill’s core behavior matches its backup purpose, and installs come from normal package sources, so this is not confirmed malware. However, it sends sensitive agent-state files to a third-party backup service, stores decryption passwords in plaintext locally, and even suggests version-control storage of that recovery file. Overall this is a coherent but high-sensitivity backup skill with meaningful confidentiality risk.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:49 PM
Package URL
pkg:socket/skills-sh/theagentservice%2Fskills%2Fopenclaw-backup%2F@05c95261a973b3b2f88d60560eedb93bce04946c