Caveat verdict
clawback
0g-clawback
The skill is designed to tar and upload entire agent workspaces (including MEMORY.md and operational state) to 0G Storage (a public immutable network) via npm scripts; while it mandates encryption before upload, the pipeline systematically pushes agent environment snapshots to an external network outside the user's direct control.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (4)
References agent memory files
SKILL.md · prose · downgraded · MEMORY.md
Popular HTTP library — network access
pnpm-lock.yaml · prose · downgraded · axios
Opens WebSocket connection
pnpm-lock.yaml · prose · downgraded · websocket
Accesses sensitive environment variables
scripts/clawback-public-upload.js · prose · downgraded · process.env.PRIVATE_KEY
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.