ClawAudit verdict
openclaw-1ly-payments
The skill seems to be setting up an integration with 1ly payments, which involves installing packages and configuring environment variables. While the intent is legitimate, the handling of sensitive information like wallet keys and API keys could pose a risk if not managed securely.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (1)
Accesses OpenClaw config/secrets directly
SKILL.md ยท frontmatter ยท ~/.openclaw/openclaw.json
Permissions & capabilities
Requires 10 environment variables. (1 sensitive: ONELY_API_KEY). Requires 3 system binaries. (1 elevated: npm).
network_inpackage_install Is this flag fair?
Thanks โ recorded.