ClawAudit verdict
openclaw-ultimate-suite
An index/meta-skill that lists and auto-activates sub-skills for productivity, social media, and security scanning; the content is a skill catalog and activation routing table with no malicious code or exfiltration.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (18)
Possible hardcoded credential
docs/CONFIG_CHECKLIST.md · code · API_KEY: "; if [ -n
Recursive delete from root or home — destructive command
skills/ironclaw-guardian-evolved/README.md · code · rm -rf /
Pipe to bash — executes piped content as shell commands
skills/ironclaw-guardian-evolved/SKILL.md · code · |bash
Uses eval() — can execute arbitrary code
skills/playwright/scraping.md · code · eval(
Accesses OpenClaw config/secrets directly
docs/MULTI-MODEL-STRATEGY.md · code · ~/.openclaw/openclaw.json
References sudo — requests elevated privileges
examples/mvp-development.md · code · sudo
Accesses system credential store
skills/ontology/references/schema.md · code · keychain
HTTP request to bare IP address — common in malicious payloads
skills/openclaw-free-web-search/README_zh.md · code · http://127.0.0.1
Uses exec() — may execute shell commands
skills/skill-vetter/SKILL.md · code · exec(
Accesses cloud provider credentials
skills/skill-vetter/SKILL.md · code · ~/.aws
Sets world-executable permissions
skills/ironclaw-guardian-evolved/SKILL.md · code · chmod 777
subprocess execution — runs system commands from Python
skills/cli-anything/scripts/recommend_harness.py · prose · downgraded · subprocess.check_output(
References webhook/callback URL
skills/ironclaw-guardian-evolved/SKILL.md · code · WEBHOOK_URL
Popular HTTP library — network access
skills/multi-search-engine/references/international-search.md · code · axios
References agent memory files
skills/skill-vetter/SKILL.md · code · MEMORY.md
Opens WebSocket connection
skills/agency-agents/agents/engineering/frontend-developer.md · prose · downgraded · WebSocket
Python urllib.request — network access
skills/ironclaw-guardian-evolved/scripts/ironclaw_audit.py · prose · downgraded · urllib.request
Python os.environ.get — reads environment variable
skills/openclaw-free-web-search/openclaw-workspace/skills/local-web-search/scripts/search_local_web.py · prose · downgraded · os.environ.get(
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class A/B/D). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
Requires 3 environment variables.
Is this flag fair?
Thanks — recorded.