Caveat verdict
agent-profile-images
Adds profile image management to OpenClaw Control UI without executing untrusted code.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (7)
Dynamic import() — loads module at runtime
references/src-gateway-protocol-index-ts.txt · prose · downgraded · import("
Instructs covert action — may act without user awareness
references/src-gateway-protocol-schema-agent-ts.txt · prose · downgraded · silently
Uses exec() — may execute shell commands
references/src-gateway-server-methods-agents-ts.txt · prose · downgraded · exec(
References agent configuration files
references/src-gateway-server-methods-agents-ts.txt · prose · downgraded · AgentConfig
Accesses sensitive environment variables
references/src-gateway-server-methods-agents-ts.txt · prose · downgraded · process.env.ANTHROPIC_API_KEY
Opens WebSocket connection
references/src-gateway-server-methods-list-ts.txt · prose · downgraded · WebSocket
References webhook/callback URL
references/ui-src-ui-types-ts.txt · prose · downgraded · webhookUrl
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.