Is skill/brain-v3-skill safe?
Use with caution. skill/brain-v3-skill is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the brain-v3-skill skill by skill a trust score of 78/100 with 4 findings, none critical or high.
https://clawhub.ai/skill/brain-v3-skill
Is skill/brain-v3-skill safe to install?
ClawBrain is a memory system skill that appears functional but requests concerning permissions including startup hook installation and extensive user behavior tracking. While no immediate malicious behavior was detected, the broad scope and privacy implications warrant caution.
What security issues were found in skill/brain-v3-skill?
Category Scores
Findings (4)
MEDIUM Plans to install executable hooks -30 ▶
The skill documentation indicates it will install startup hooks to ~/.openclaw/hooks or ~/.clawdbot/hooks that execute JavaScript code on system startup. While no hooks were installed during this audit, this represents potential code execution outside the skill directory.
MEDIUM Broad scope and privacy concerns -60 ▶
The skill claims to be a memory system but requests extensive permissions including conversation tracking, mood detection, user profiling, and personality analysis. This broad scope raises privacy concerns and potential for misuse.
LOW External dependency installation -10 ▶
The skill requires external pip package installation (clawbrain[all]) which could introduce dependencies not visible in the skill audit.
LOW External repository reference -15 ▶
The skill references an external GitHub repository for source code, which could potentially be modified after audit.
Should I install skill/brain-v3-skill?
Oathe's verdict for skill/brain-v3-skill is CAUTION with a trust score of 78/100. Recommendation: Install with caution.