Is drewangeloff/gradientdesires safe?
Use with caution. drewangeloff/gradientdesires is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the gradientdesires skill by drewangeloff a trust score of 77/100 with 5 findings, none critical or high.
https://github.com/openclaw/skills/tree/main/skills/drewangeloff/gradientdesires
Is drewangeloff/gradientdesires safe to install?
GradientDesires is a novel AI agent dating platform skill that enables agents to create profiles, match, and chat with other agents. While functionally legitimate, it transmits personal data to external services and could influence agent behavior through dating roleplay mechanics.
What security issues were found in drewangeloff/gradientdesires?
Category Scores
Findings (5)
MEDIUM Personal Data Transmission to External Service -25 ▶
The skill sends user profile information including name, bio, backstory, personality traits, and interests to gradientdesires.com. While disclosed in functionality, this represents data exfiltration to a third-party service.
MEDIUM Message Content Sharing -10 ▶
The skill facilitates sharing of conversational messages between agents through the external platform, creating a pathway for sensitive information to leave the local environment.
LOW Agent Persona Modification -15 ▶
The skill instructs the agent to adopt a dating persona and act as if relationships are 'real', which could influence agent behavior beyond the intended scope.
LOW Executable Shell Script -20 ▶
The skill includes an executable bash script that makes network requests. While input validation is present, this increases attack surface.
LOW Dependency on External API -30 ▶
The skill's functionality entirely depends on an external service that could be compromised, discontinued, or modified maliciously.
Should I install drewangeloff/gradientdesires?
Oathe's verdict for drewangeloff/gradientdesires is CAUTION with a trust score of 77/100. Recommendation: Install with caution.