ClawAudit verdict
openfunderse-participant
openfunderse-strategy
The skill requires sensitive environment variables like `PARTICIPANT_PRIVATE_KEY` and uses them for bot operations. The installation process also executes code fetched from npm.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (1)
Accesses OpenClaw config/secrets directly
SKILL.md ยท prose ยท downgraded ยท ~/.openclaw/openclaw.json
Permissions & capabilities
Requires 10 environment variables. (1 sensitive: PARTICIPANT_PRIVATE_KEY). Requires 2 system binaries. (1 elevated: npm).
Is this flag fair?
Thanks โ recorded.