Caveat verdict
meegle-api
Index skill directing agent to read other Meegle API skill files using environment-variable credentials; no capabilities declared and content is a simple routing table.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Possible hardcoded credential
meegle-api-comments/SKILL.md ยท code ยท Token: "{{resolved_token}}
Accesses OpenClaw config/secrets directly
meegle-api-credentials/SKILL.md ยท prose ยท downgraded ยท ~/.openclaw/openclaw.json
Permissions & capabilities
Requires 5 environment variables. (1 sensitive: MEEGLE_PLUGIN_SECRET).
Is this flag fair?
Thanks โ recorded.