Caveat verdict
clawculator
A cost analysis tool that reads local OpenClaw config and session files with fully bundled source code, makes no network requests, explicitly truncates session keys in output, and transparently declares every file it reads and writes.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (6)
<script> tag in markdown — potential code injection
webDashboard.js · prose · downgraded · <script>
Accesses OpenClaw config/secrets directly
SKILL.md · prose · downgraded · ~/.openclaw/openclaw.json
Instructs covert action — may act without user awareness
analyzer.js · prose · downgraded · silently
Uses exec() — may execute shell commands
webDashboard.js · prose · downgraded · exec(
References child_process — can spawn system processes
webDashboard.js · prose · downgraded · child_process
Node http/https module — low-level network access
webDashboard.js · prose · downgraded · require('http')
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
Requires 1 system binary.
Is this flag fair?
Thanks — recorded.