ClawAudit verdict
openclaw-elsa-x402
elsa-x402-api
Requires a PAYMENT_PRIVATE_KEY to sign transactions and can move funds, which is elevated financial access.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
Possible hardcoded credential
scripts/__tests__/confirm.test.ts · prose · downgraded · token: '0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
Accesses OpenClaw config/secrets directly
README.md · prose · downgraded · ~/.openclaw/openclaw.json
Popular HTTP library — network access
package.json · prose · downgraded · axios
Permissions & capabilities
Requires 1 environment variable. (1 sensitive: PAYMENT_PRIVATE_KEY).
Is this flag fair?
Thanks — recorded.