ClawAudit verdict
openclaw-push-doctor
The skill provides self-diagnostic checks for OpenClaw's communication channels and scheduled tasks, with no evidence of malicious behavior.
β Flagged for review β coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis β not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
Possible hardcoded credential
scripts/check-telegram.js Β· prose Β· downgraded Β· TOKEN='ζ¨ηζ°token
Pipe to python β executes piped content as Python code
scripts/check-wechat.js Β· prose Β· downgraded Β· | python3
References sudo β requests elevated privileges
scripts/fix-crons.js Β· prose Β· downgraded Β· sudo
Permissions & capabilities
No declared permissions β minimal attack surface.
Is this flag fair?
Thanks β recorded.