ClawAudit verdict
maylo-voice-assistant
A local offline-first voice assistant that uses local ASR, TTS, and WebSocket audio streaming on the user's own machine; the skill explicitly states it ships no secrets and all components are local.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
Opens WebSocket connection
SKILL.md ยท frontmatter ยท WebSocket
subprocess execution โ runs system commands from Python
assets/app/bridge/milo_responder_openclaw.py ยท prose ยท downgraded ยท subprocess.run(
Python os.getenv โ reads environment variable
assets/app/bridge/milo_responder_openclaw.py ยท prose ยท downgraded ยท os.getenv(
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution โ cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
No declared permissions โ minimal attack surface.
Is this flag fair?
Thanks โ recorded.