ClawAudit verdict

wip-1password

88
🟢 Trusted
Low risk — reviewed by ClawAudit, behavior matches stated purpose

1Password secrets integration using the official JS SDK with service accounts; secrets are resolved in memory only and never written to disk.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

5
security
60
transparency
80
maintenance

Permission integrity

Code accesses API keys/tokens but declares no environment variables

credential_access

Findings (4)

Pattern match critical

Possible hardcoded credential

SKILL.md · code · apiKey: "op://Agent Secrets/OpenAI API/api key

Pattern match high

Accesses OpenClaw config/secrets directly

ai/_trash/README--before-format--2026-03-12.md · code · ~/.openclaw/openclaw.json

Pattern match high

References child_process — can spawn system processes

ai/_trash/README--before-format--2026-03-12.md · code · child_process

Pattern match medium

Accesses sensitive environment variables

ai/_trash/README--before-format--2026-03-12.md · code · process.env.OPENAI_API_KEY

Why the tier is capped

Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.

Permissions & capabilities

Requires 1 system binary.

credential_access

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API