ClawAudit verdict
bulletin-tools
The skill provides a multi-agent bulletin board for posting bulletins, subscribing agents, and running structured discussions.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (5)
Instructs covert action — may act without user awareness
SKILL.md · prose · downgraded · silently
Uses exec() — may execute shell commands
lib/bulletin-db.ts · prose · downgraded · exec(
Accesses OpenClaw config/secrets directly
README.md · prose · downgraded · ~/.openclaw/.env
Opens WebSocket connection
README.md · code · WebSocket
Accesses sensitive environment variables
index.ts · prose · downgraded · process.env.RELAY_BOT_TOKEN
Permissions & capabilities
Requires 3 environment variables. (3 sensitive: DISCORD_BOT_TOKEN, GATEWAY_AUTH_TOKEN, RELAY_BOT_TOKEN). Requires 1 system binary.
Is this flag fair?
Thanks — recorded.