Caveat verdict
openclaw-setup
Accesses credentials AND makes external network calls
AWS provisioning and OpenClaw setup guide that walks users through EC2 launch, SSH configuration, API key setup, and Telegram bot creation; all steps are transparent and user-directed with explicit confirmation before each phase.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but Caveat detects co-occurrence โ it does not verify that one flows into another. Read the code to confirm a live chain.
Accesses credentials AND makes external network calls โ potential credential theft
LLM02 ยท ASI03
Accesses credentials AND writes files โ may persist stolen credentials locally
LLM02 ยท LLM06 ยท ASI03
Permission integrity
network_out
file_read+write
credential_access
package_install
Findings (2)
References sudo โ requests elevated privileges
SKILL.md ยท code ยท sudo
References agent memory files
SKILL.md ยท prose ยท downgraded ยท MEMORY.md
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class F). Final tier capped at Caution โ cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_outfile_writepackage_installcredential_access Thanks โ recorded.