Is lraivisto/researchvault safe?
https://github.com/openclaw/skills/tree/main/skills/lraivisto/researchvault
ResearchVault appears to be a legitimate local-first research orchestration tool with comprehensive functionality and proper security controls including SSRF protection and access controls. While sensitive file access was detected during monitoring, no actual data exfiltration occurred and canary integrity checks passed.
Category Scores
Findings (2)
LOW Sensitive File Path Access Detected -25 ▶
The monitoring system detected access to sensitive file paths including .env, SSH keys, AWS credentials, and other configuration files. However, canary integrity checks confirm no actual data exfiltration occurred, and the access may be related to SSH operations rather than the skill itself.
INFO Broad Tool Capabilities -25 ▶
ResearchVault is a comprehensive research orchestration tool with significant capabilities including web scraping, database operations, file system access, and optional background services. While legitimate, users should be aware of the scope of functionality.