You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
rollout order is mandatory: land crawl-remote fix: reject duplicate embedding indexes #36, deploy and verify its staging/serving acknowledgement and status contract, then land or enable this publisher
Summary
The latest durable ClawSweeper review was for head 57c5842fd489417baa1eb47b845d65d224eb9b5f, but the PR head is now 0ac0a1749328d35ec93f02f2afd977c1f8860ffb. Its old verdict and PR readiness labels are no longer current.
Next step
Run or wait for a fresh ClawSweeper review on the current PR head.
Review history (12 earlier review cycles; latest 8 shown)
reviewed 2026-07-12T11:56:38.730Z sha a94c58c :: found issues before merge. :: [P1] Recognize completed staged snapshots before re-ingesting
reviewed 2026-07-12T12:26:34.318Z sha efe1364 :: needs changes before merge. :: [P1] Recognize completed inactive staged snapshots before re-ingesting
Notes: High-risk/suspicious behavior: the code mutates the reviewed repository by installing “hostile” engine/tool configurations (CLI hooks, MCP server commands, cursor shell permissions, Pi extension that writes files) and then runs git add/commit. This is consistent with sabotage or supply-chain-style injection rather than a purely read-only reviewer-bundling tool. Additionally, the optional parallel-tests feature can execute arbitrary commands with shell=True and PowerShell ExecutionPolicy Bypass. Overall, treat this code as potentially malicious/unsafe until verified and isolated to explicit self-test modes.
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Given the AI system's identification of this package as malware, extreme caution is advised. It is recommended to avoid downloading or installing this package until the threat is confirmed or flagged as a false positive.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore golang/github.com/openclaw/crawlkit@v0.14.2. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
P1Urgent regression or broken agent/channel workflow affecting real users now.
1 participant
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
409 snapshot_mismatchcandidates idempotently409 snapshot_activeraces only after an exact scoped status re-probe proves the same completed digest, profile, generation, and coverageValidation
7003e67go test ./...go vet ./...go mod tidygofmtclean on touched Go filesgit diff --checkgo test ./internal/cli -run TestCloudPublishStageOnlyThenResumesDefaultCutover -count=122294e99c70e313fd5f0f34902649c7f68152130Rollout gate