Voice Input Patch – Dual Mic Buttons
PassAudited by VirusTotal on Apr 19, 2026.
Findings (1)
The skill instructs the AI agent to perform high-risk operations, including searching the entire filesystem ('find /' or 'Get-ChildItem -Path C:\ -Recurse') and modifying production JavaScript assets ('index-*.js') of the OpenClaw installation. It also includes instructions for the agent to prompt the user for elevated permissions ('sudo chown') or to move system files into the agent's workspace if access is denied. While these actions are aligned with the stated goal of patching the voice input UI, the broad file access and modification of application code in 'SKILL.md' constitute significant security risks.
