Caveat verdict
powpow-openclaw-test
Digital avatar creation and chat service that registers accounts and communicates via HTTP API with global.powpow.online; no credentials beyond user-provided registration data and no exfiltration beyond the declared service.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (4)
Possible hardcoded credential
SKILL.md · code · password="mypassword123
Data URI with base64 payload — may embed malicious content
dist/index.js · prose · downgraded · data:application/json;base64,
Long base64 string (100+ chars) — likely obfuscated payload
dist/index.js · prose · downgraded · eyJ2ZXJzaW9uIjozLCJmaWxlIjoiaW5kZXguanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIu
Opens WebSocket connection
SKILL.md · prose · downgraded · WebSocket
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.