ClawAudit verdict
openclaw_kraken
kraken-cli
The skill uses a Bash CLI to query Kraken APIs, inspect account state, and run trading actions, with secrets provided via environment variables.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Possible hardcoded credential
test/signature_example.sh ยท prose ยท downgraded ยท SECRET="kQH5HW/8p1uGOVjbgWA7FunAmGO8lsSUXNsu3eow76sz84Q18fWxnyRzBHCd3pd5nE9qa99H
Opens WebSocket connection
SKILL.md ยท frontmatter ยท websocket
Permissions & capabilities
Requires 1 environment variable. Requires 3 system binaries. (1 elevated: curl).
Is this flag fair?
Thanks โ recorded.