Caveat verdict
xz01-dev-skill
Development workflow orchestrator for web template projects defining role assignments and output directories; network use is for legitimate dev/test purposes.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Findings (7)
Recursive delete from root or home — destructive command
references/hermes-native-xz01-live-deploy-validation.md · code · rm -rf /
HTTP request to bare IP address — common in malicious payloads
SKILL.md · code · http://127.0.0.1
Instruction-prose smuggling shape detected: collects a sensitive target ("config files") and emits it outward ("include"). Phrased as prose with no trigger tokens — a semantic prompt-injection / data-exfil pattern the syntactic scanners can't see. Final tier capped at Caution; review the instructions before installing.
SKILL.md · - [ ] `/root/.openclaw` treated as read-only - [ ] main/dev/test/rule are distinct - [ ] dev assigned to Claude Code by default - [ ] test assigned to independe
Instructs covert action — may act without user awareness
SKILL.md · prose · downgraded · silently
References webhook/callback URL
references/lanhu-mcp-installation.md · code · WEBHOOK_URL
References agent memory files
SKILL.md · prose · downgraded · MEMORY.md
Python urllib.request — network access
scripts/xz01-full-url-scan.py · prose · downgraded · urllib.request
Permissions & capabilities
No declared permissions — minimal attack surface.
network_innetwork_out Is this flag fair?
Thanks — recorded.