Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/superlore.mjs:45
Security audit
Security checks across malware telemetry and agentic risk
This skill connects OpenClaw to Superlore for private podcast creation and upload, with disclosed credential storage and user-directed access.
Before installing, understand that pairing grants OpenClaw a Superlore agent credential for the scopes you approve. Use the minimum scopes needed, treat listen URLs as private, and only authorize uploads or recurring schedules when you intend them.
65/65 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access