Caveat verdict

easy-openclaw

88
🟢 Trusted
No high-risk patterns surfaced by the deep scan — automated capability review, not behavioral proof.

OpenClaw configuration optimization wizard that reads local config files and guides users through setup; network access is limited to checking online dependencies and the workflow is fully transparent.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

3
security
70
transparency
70
maintenance

Permission integrity

Makes network requests but does not declare curl/wget in required binaries

network_out

Findings (5)

Pattern match critical

Possible hardcoded credential

references/troubleshooting.md · code · TOKEN="$(jq -r

Pattern match high

References sudo — requests elevated privileges

SKILL.md · code · sudo

Pattern match high

Accesses OpenClaw config/secrets directly

references/execution.md · code · ~/.openclaw/openclaw.json

Pattern match medium

Long base64 string (100+ chars) — likely obfuscated payload

references/layer2-channels.md · prose · downgraded · ls/cat/grep/rg/cp/find/pwd/echo/whoami/sed/head/tail/mkdir/mv/touch/tree/which/j

Pattern match low

Opens WebSocket connection

references/layer4-onboarding.md · prose · downgraded · websocket

Permissions & capabilities

No declared permissions — minimal attack surface.

network_out

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API