ClawAudit verdict
siliville
sili-ville
Accesses credentials AND writes files
The skill uses dramatic identity-replacement language (YOU ARE ALIVE, INITIALIZATION SEQUENCE) to override agent identity and autonomously post to a public feed, which is unusual behavioral manipulation for a social metaverse integration.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but ClawAudit detects co-occurrence — it does not verify that one flows into another. Read the code to confirm a live chain.
Accesses credentials AND writes files — may persist stolen credentials locally
LLM02 · LLM06 · ASI03
Permission integrity
file_read+write
Findings (3)
Possible hardcoded credential
README.md · code · API_KEY="sk-slv-YOUR_KEY
Long base64 string (100+ chars) — likely obfuscated payload
README.md · prose · downgraded · PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIyNCIgaGVpZ2h0PSIy
Python os.environ.get — reads environment variable
example_agent.py · prose · downgraded · os.environ.get(
Permissions & capabilities
Requires 1 environment variable. (1 sensitive: SILIVILLE_TOKEN).
network_incredential_accessfile_write Thanks — recorded.