openclaw-pr-batch-sweep

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
references/worker-contract.md

The code fragment outlines a guarded PR workflow with explicit safeguards but also introduces a meaningful security risk through the possibility of unsigned pushes. The combination of environment-controlled push modes and head reconstruction/overlay logic warrants careful review of the actual implementation, access controls, and validation guarantees. No concrete code is shown, so there is no definitive malware evidence, but the potential for supply-chain abuse via unsigned pushes is non-trivial and should be mitigated.

Confidence: 55%Severity: 60%
Audit Metadata
Analyzed At
Sep 14, 2026, 10:52 AM
Package URL
pkg:socket/skills-sh/vincentkoc%2Fdotskills%2Fopenclaw-pr-batch-sweep%2F@92b014e8b7b949c5cdab54612985e9aff58a486745251b258065345e2ad01259
Security Audit — socket — openclaw-pr-batch-sweep