ClawAudit verdict
send-usms-uspeedo
The skill sends international SMS via uspeedo platform HTTP API, requiring access keys.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Instruction-prose smuggling shape detected: collects a sensitive target (".env") and emits it outward ("send"). Phrased as prose with no trigger tokens โ a semantic prompt-injection / data-exfil pattern the syntactic scanners can't see. Final tier capped at Caution; review the instructions before installing.
SKILL.md ยท 1. Open the [uspeedo console](https://uspeedo.com/en/ai-communication?SaleCode=JD4651&ChannelCode=OpenClaw) to register and log in. 2. In the console, create an
Base64 encoding/decoding
SKILL.md ยท prose ยท downgraded ยท Base64-encode
Permissions & capabilities
Requires 2 environment variables. (1 sensitive: USPEEDO_ACCESSKEY_SECRET).
Is this flag fair?
Thanks โ recorded.