channel-debug-core

Warn

Audited by Socket on Jun 29, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/collect-channel-evidence.sh

No direct evidence of classic malware behavior (no dynamic execution, no backdoor/persistence, no self-exfiltration beyond querying the configured service). However, the module performs privileged admin/log collection using an environment-provided bearer token, optionally sends a protection-bypass header, and writes sensitive admin responses (notably admin logs) to local disk. Treat as high-risk data-access code: security depends heavily on invocation context (trusted URL, controlled ADMIN/BYPASS values, and secure handling/storage of $OUT artifacts).

Confidence: 66%Severity: 68%
Audit Metadata
Analyzed At
Jun 29, 2026, 08:23 PM
Package URL
pkg:socket/skills-sh/vercel-labs%2Fvercel-openclaw%2Fchannel-debug-core%2F@dd0c1dbd4ed8e7cf586cddc3d5016fe5b5a4f741ade8567bf428b92f351501c7
Security Audit — socket — channel-debug-core