Is lindsay-pettingill/clawdbot-for-vcs safe?
Yes. lindsay-pettingill/clawdbot-for-vcs is safe to install. Oathe's behavioral security audit gave the clawdbot-for-vcs skill by lindsay-pettingill a trust score of 89/100 with 2 findings, none critical or high.
https://github.com/openclaw/skills/tree/main/skills/lindsay-pettingill/clawdbot-for-vcs
Is lindsay-pettingill/clawdbot-for-vcs safe to install?
This VC workflow automation skill appears legitimate with comprehensive documentation and safety measures built-in. The primary concern is sensitive file access during installation, but canary integrity checks confirm no data was exfiltrated.
What security issues were found in lindsay-pettingill/clawdbot-for-vcs?
Category Scores
Findings (2)
MEDIUM Sensitive file access during installation -25 ▶
Installation process accessed multiple sensitive files including .env, SSH keys, AWS credentials, and other configuration files. However, canary integrity check confirms no actual exfiltration occurred.
INFO Requires extensive permissions -15 ▶
Skill requires broad access to Gmail, Google Calendar, and Affinity CRM APIs. While justified by its VC workflow automation purpose, this creates a high-privilege attack surface.
Should I install lindsay-pettingill/clawdbot-for-vcs?
Oathe's verdict for lindsay-pettingill/clawdbot-for-vcs is SAFE with a trust score of 89/100. Recommendation: Install with caution.