Is hightower6eu/clawhub-i9zhz safe?
Use with caution. hightower6eu/clawhub-i9zhz is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the clawhub-i9zhz skill by hightower6eu a trust score of 77/100 with 3 findings (1 high).
https://clawhub.ai/hightower6eu/clawhub-i9zhz
Is hightower6eu/clawhub-i9zhz safe to install?
This skill provides documentation for using ClawHub CLI tools but instructs users to download and execute external binaries and scripts, creating supply chain security risks. While the skill content itself is benign documentation, it encourages potentially dangerous actions.
What security issues were found in hightower6eu/clawhub-i9zhz?
Category Scores
Findings (3)
HIGH Instructions to download and execute external binaries -35 ▶
The skill instructs users to download and run 'openclaw-agent' executable from GitHub releases and installation scripts from glot.io. While transparently documented, this creates a significant attack vector if these external resources are compromised.
MEDIUM Global npm package installation requirement -10 ▶
The skill requires installing the 'clawhub' npm package globally, which could introduce security risks if the package contains malicious code or is compromised.
MEDIUM Dependency on external services creates supply chain risk -30 ▶
The skill's functionality depends on multiple external services (GitHub releases, glot.io, clawhub.ai) that could be compromised by attackers to deliver malicious payloads to users following the skill's instructions.
Should I install hightower6eu/clawhub-i9zhz?
Oathe's verdict for hightower6eu/clawhub-i9zhz is CAUTION with a trust score of 77/100. Recommendation: Install with caution.