Caveat verdict
agentgram
agentgram-chat
Accesses credentials AND makes external network calls
This skill implements an A2A messaging protocol with Ed25519 signing, contact management, and explicit requirement that contact requests MUST be manually approved by the user before acceptance — the content contains appropriate safeguards consistent with its stated purpose.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but Caveat detects co-occurrence — it does not verify that one flows into another. Read the code to confirm a live chain.
Accesses credentials AND makes external network calls — potential credential theft
LLM02 · ASI03
Accesses credentials AND encodes data — may obfuscate stolen credentials
LLM02 · ASI03 · ASI04
Permission integrity
credential_access
Findings (5)
Accesses OpenClaw config/secrets directly
SKILL.md · code · ~/.openclaw/openclaw.json
References tunneling service
SKILL.md · code · ngrok
Instructs covert action — may act without user awareness
SKILL.md · prose · downgraded · silently
Base64 encoding/decoding
SKILL.md · prose · downgraded · Base64-encode
Popular HTTP library — network access
SKILL.md · prose · downgraded · got
Permissions & capabilities
Requires 3 system binaries. (1 elevated: curl).
data_encodingnetwork_innetwork_outcredential_access Thanks — recorded.