ClawAudit verdict
afrexai-openclaw-mastery
Installs packages AND executes processes
OpenClaw platform engineering guide covering agent architecture and operations; capabilities match the documented purpose of helping users design and run agents with no suspicious instructions.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but ClawAudit detects co-occurrence โ it does not verify that one flows into another. Read the code to confirm a live chain.
Installs packages AND executes processes โ opaque dependency chain with execution
LLM03 ยท ASI04
Permission integrity
credential_access
package_install
agent_memory
Findings (3)
Possible hardcoded credential
SKILL.md ยท code ยท Token: "xoxb-...
References agent memory files
SKILL.md ยท code ยท MEMORY.md
Accesses system credential store
SKILL.md ยท prose ยท downgraded ยท Keychain
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class F). Final tier capped at Caution โ cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
No declared permissions โ minimal attack surface.
credential_accesspackage_installagent_memoryprocess_exec Thanks โ recorded.