Caveat verdict
autonomous-loop
The skill provides functionality for an OpenClaw agent to work continuously without human intervention. It does not show evidence of malicious intent and operates within defined parameters.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Opens WebSocket connection
SKILL.md ยท code ยท WebSocket
Accesses OpenClaw config/secrets directly
SKILL.md ยท prose ยท downgraded ยท ~/.openclaw/openclaw.json
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_in Is this flag fair?
Thanks โ recorded.