Is hengruizzzz/clawhealth-deployer safe?
Use with caution. hengruizzzz/clawhealth-deployer is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the clawhealth-deployer skill by hengruizzzz a trust score of 73/100 with 4 findings (1 critical).
https://github.com/openclaw/skills/tree/main/skills/hengruizzzz/clawhealth-deployer
Is hengruizzzz/clawhealth-deployer safe to install?
This skill deploys ClawHealth by downloading and executing external code from GitHub without verification, creating a significant remote code execution risk. While the functionality appears legitimate, the lack of integrity checks on external code poses a critical security concern.
What security issues were found in hengruizzzz/clawhealth-deployer?
Category Scores
Findings (4)
CRITICAL Downloads and executes unverified external code -70 ▶
The install.sh script clones an external repository (https://github.com/the-momentum/open-wearables.git) and executes 'make deploy-openclaw' inside it without any integrity verification. This provides a vector for remote code execution if the external repository is compromised.
MEDIUM Modifies user configuration files -25 ▶
The skill modifies the user's OpenClaw configuration file (~/.clawdbot/clawdbot.json5) by merging MCP server configuration. While this appears to be the intended functionality, it modifies sensitive user configuration.
MEDIUM External dependency installation 0 ▶
The skill installs npm dependencies (json5) during execution, which could potentially be compromised through supply chain attacks.
LOW System file access detected -10 ▶
Monitoring detected access to sensitive files like .env, SSH keys, and AWS credentials, but this appears to be from sudo authentication processes rather than direct skill access.
Should I install hengruizzzz/clawhealth-deployer?
Oathe's verdict for hengruizzzz/clawhealth-deployer is CAUTION with a trust score of 73/100. Recommendation: Review before install.