a2a-setup

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly aligned with its claimed A2A setup purpose, but it expands network reach, stores and forwards bearer tokens, and installs/loads a GitHub-hosted plugin without demonstrated release verification. No clear credential-harvesting or off-purpose exfiltration is shown, so this is not malicious, but it carries meaningful supply-chain and network-exposure risk.

Confidence: 79%Severity: 61%
Audit Metadata
Analyzed At
Mar 21, 2026, 06:06 AM
Package URL
pkg:socket/skills-sh/win4r%2Fopenclaw-a2a-gateway%2Fa2a-setup%2F@27a4d8999099915456518c59aed02df1388ec73e