Caveat verdict
clawd-migrate
The skill provides a clear migration process from moltbot or clawdbot to openclaw, including discovery, backup, migration, verification, and reinstallation of openclaw. It uses standard file operations and does not contain any suspicious or malicious code.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (4)
References child_process — can spawn system processes
bin/clawd-migrate.js · prose · downgraded · child_process
subprocess execution — runs system commands from Python
openclaw_setup.py · prose · downgraded · subprocess.run(
subprocess with shell=True — command injection vector
openclaw_setup.py · prose · downgraded · subprocess.run(
"npm install -g openclaw",
capture_outpu
References agent memory files
SKILL.md · prose · downgraded · MEMORY.md
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.