Back to skill

Security audit

Anydef Enc

Security checks for vulnerabilities and agentic risk

Overview

This is a local encryption skill with no exfiltration signs, but its advertised key-rotation helper does not actually rotate keys.

Review before installing. The local-only encryption code does not show network exfiltration or automatic execution, but do not rely on its master-key rotation or recovery helper for passphrase compromise or incident response. Confirm how your OpenClaw environment implements window.storage, especially whether storage is synced or shared, and keep a backup plan because lost passphrases make encrypted data unrecoverable.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.