ClawAudit verdict
openclaw-leaderboard
The skill submits earnings to a public leaderboard, using network access for a legitimate purpose.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Findings (2)
Dynamic import() โ loads module at runtime
src/app/api/v1/submissions/route.ts ยท prose ยท downgraded ยท import("
Accesses sensitive environment variables
openclaw-skill/tool.js ยท prose ยท downgraded ยท process.env.OPENCLAW_API_KEY
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_out Is this flag fair?
Thanks โ recorded.