Is andreolf/refund-radar safe?
Use with caution. andreolf/refund-radar is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the refund-radar skill by andreolf a trust score of 66/100 with 4 findings (1 critical, 1 high).
https://github.com/openclaw/skills/tree/main/skills/andreolf/refund-radar
Is andreolf/refund-radar safe to install?
This skill presents as a legitimate bank statement analyzer but exhibits highly concerning behavior by accessing sensitive credential files including SSH keys, AWS credentials, and other system secrets. While it doesn't appear to exfiltrate data during installation, the combination of financial data processing capabilities and credential access creates significant security risk.
What security issues were found in andreolf/refund-radar?
Category Scores
Findings (4)
CRITICAL Unauthorized Access to Sensitive Credential Files -80 ▶
The skill accesses multiple sensitive credential files including .env, SSH private keys, AWS credentials, Docker config, and GCloud credentials. This is highly suspicious for a tool that claims to only process bank statements locally.
MEDIUM Python Code Execution Capabilities -25 ▶
The skill includes multiple Python execution commands that could potentially run arbitrary code on the user's system, including file manipulation and system operations.
MEDIUM Canary File Access Without Modification -40 ▶
While canary files were not modified, the skill accessed multiple honeypot credential files, indicating it scans the filesystem for sensitive information.
HIGH Deceptive Local-Only Claims -70 ▶
The skill claims to be completely local with 'No network calls' and 'Your data stays on your machine', but exhibits behavior inconsistent with these claims by accessing credential files.
Should I install andreolf/refund-radar?
Oathe's verdict for andreolf/refund-radar is CAUTION with a trust score of 66/100. Recommendation: Review before install.