openclaw-pr-batch-sweep
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalyreferences/worker-contract.md
LOWAnomalyLOW
references/worker-contract.md
The code fragment outlines a guarded PR workflow with explicit safeguards but also introduces a meaningful security risk through the possibility of unsigned pushes. The combination of environment-controlled push modes and head reconstruction/overlay logic warrants careful review of the actual implementation, access controls, and validation guarantees. No concrete code is shown, so there is no definitive malware evidence, but the potential for supply-chain abuse via unsigned pushes is non-trivial and should be mitigated.
Confidence: 55%Severity: 60%
Audit Metadata