Is clawbow/bitwarden-secrets safe?
Yes. clawbow/bitwarden-secrets is safe to install. Oathe's behavioral security audit gave the bitwarden-secrets skill by clawbow a trust score of 93/100 with 3 findings, none critical or high.
https://github.com/openclaw/skills/tree/main/skills/clawbow/bitwarden-secrets
Is clawbow/bitwarden-secrets safe to install?
This Bitwarden secrets management skill implements legitimate functionality with reasonable safety controls for credential handling. While monitoring detected suspicious file access timing, the skill code itself appears clean and canary files remained intact. The skill includes proper safety mechanisms to prevent accidental secret exposure.
What security issues were found in clawbow/bitwarden-secrets?
Category Scores
Findings (3)
MEDIUM Sensitive file access detected during audit -20 ▶
Monitoring detected access to sensitive credential files (.env, SSH keys, AWS credentials, Docker config, GCloud credentials) during the audit timeframe. However, the skill code itself does not contain logic to access these files, and canary files remained intact.
MEDIUM Credential handling functionality -15 ▶
The skill is designed to interact with Bitwarden/Vaultwarden secrets, which inherently involves handling sensitive credential data. While safety controls are implemented (VW_REVEAL_ALLOW + explicit confirmation), this functionality carries inherent risk.
LOW Executable scripts included -5 ▶
The skill contains Python and shell scripts that execute external commands, specifically the 'bw' CLI tool. This is expected functionality but represents potential attack surface.
Should I install clawbow/bitwarden-secrets?
Oathe's verdict for clawbow/bitwarden-secrets is SAFE with a trust score of 93/100. Recommendation: Install with caution.