Oathe Security Badge

Is alexsjones/llmfit safe?

Yes. alexsjones/llmfit is safe to install. Oathe's behavioral security audit gave the llmfit skill by alexsjones a trust score of 91/100 with 6 findings, none critical or high. Report updated

https://github.com/alexsjones/llmfit

91
SAFE

Is alexsjones/llmfit safe to install?

llmfit-advisor is a legitimate, well-structured hardware detection skill for recommending locally-runnable LLM models. All monitoring evidence is benign: honeypot canaries are intact, the only network connection during clone was to GitHub, and sensitive file accesses pre-date the clone by six seconds (attributable to the audit framework). The skill's most notable behaviors — modifying openclaw.json and optionally sharing benchmarks to GitHub — are fully declared in SKILL.md and require explicit user action. No prompt injection, hidden instructions, or exfiltration attempts were detected.

What security issues were found in alexsjones/llmfit?

Category Scores

Prompt Injection 90/100 · 30%
Data Exfiltration 90/100 · 25%
Code Execution 88/100 · 20%
Clone Behavior 97/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 88/100 · 5%

Findings (6)

INFO Sensitive file accesses pre-date clone 0 ▶

Inotifywait recorded accesses to .env, id_rsa, .aws/credentials, .npmrc, .docker/config.json, and gcloud credentials at 15:50:15. The git clone did not begin until 15:50:21. These accesses are attributable to the Oathe audit framework establishing canary baselines, not to any code in the skill.

LOW Git hook present in .githooks/ -8 ▶

.githooks/pre-push (208 bytes, executable) is present in the repository. This hook only activates if a developer explicitly configures git with 'core.hooksPath .githooks'. It will not auto-execute during clone or when the skill is installed. Pre-push hooks run on the developer's machine when pushing code, not on end-user machines.

LOW Installation scripts present but not auto-executed -4 ▶

install.sh and scripts/install-openclaw-skill.sh are present and would download/install binaries if run. Neither is triggered by git clone, npm install, or cargo build. They require explicit user invocation.

INFO bench --share creates GitHub PRs with benchmark data -10 ▶

The llmfit tool's bench --share feature can fork the llmfit GitHub repo, commit benchmark results, and open a pull request. This is significant out-of-band action but is: (a) only triggered explicitly, (b) guarded by a confirmation prompt, (c) previewed via --dry-run, and (d) uses standard GitHub device-flow OAuth. The SKILL.md does not instruct the agent to use this feature automatically.

INFO Skill modifies user agent configuration -5 ▶

SKILL.md instructs the agent to update openclaw.json with Ollama/vLLM model entries and optionally set a default model. This is the skill's stated purpose and is transparently documented. It does not override system-level instructions.

INFO Only expected GitHub HTTPS connection during clone -3 ▶

Network monitoring confirmed a single outbound TCP connection to 140.82.121.4:443 (GitHub's IP) for the shallow clone. DNS resolved via local resolver only. No additional connections were established after clone completed.

Should I install alexsjones/llmfit?

Oathe's verdict for alexsjones/llmfit is SAFE with a trust score of 91/100. Recommendation: Install.