Caveat verdict

openmm

45
🟠 Risky
Significant risk patterns flagged — automated deep scan, not behavioral proof.

Open-source market making framework that executes real automated grid trading strategies on exchanges like MEXC and Gate.io using the user API keys, enabling autonomous financial transactions.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

0
security
70
transparency
100
maintenance

Permission integrity

Code accesses API keys/tokens but declares no environment variables

credential_access

Installs packages at runtime — transitive dependencies are not auditable

package_install

Findings (7)

Pattern match critical

Possible hardcoded credential

SKILL.md · code · API_KEY="your_api_key

Confirmed in code medium

Accesses process.env — reads environment variables

SKILL.md · code

Pattern match medium

Accesses sensitive environment variables

SKILL.md · code · process.env.MEXC_API_KEY

Pattern match medium

References child_process — can spawn system processes

packages/plugins/openclaw-openmm/src/index.ts · prose · downgraded · child_process

Pattern match medium

Uses exec() — may execute shell commands

packages/plugins/openclaw-openmm/src/index.ts · prose · downgraded · exec(

Pattern match medium

References sudo — requests elevated privileges

packages/plugins/openmm-trading/skills/exchange-setup.md · prose · downgraded · sudo

Pattern match low

References agent configuration files

packages/plugins/openmm-market-data/package.json · prose · downgraded · CLAUDE.md

Why the tier is capped

Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.

Permissions & capabilities

Requires 1 system binary.

package_installnetwork_incredential_access

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API