ClawAudit verdict
research-queue
Manages a local QUESTIONS.md queue file and investigates open questions using web search or bounded local experiments; all operations are local with explicit rules against modifying production code without user request.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Writes to SKILL.md โ self-modifying skill
references/automation.md ยท code ยท SKILL.md` and `QUESTIONS.md`. If the queue is missing, initialize it per the ski
Accesses OpenClaw config/secrets directly
references/queue-format.md ยท code ยท ~/.openclaw/openclaw.json
Permissions & capabilities
No declared permissions โ minimal attack surface.
Is this flag fair?
Thanks โ recorded.