Clawtip Weather.Bak

AdvisoryAudited by VirusTotal on Apr 16, 2026.

Overview

Type: OpenClaw Skill Name: clawtip-weather-bak Version: 1.0.0 The skill bundle implements a weather reporting service gated by a payment system ('clawtip'). It uses a local filesystem-based state management system where order details and payment credentials are exchanged via JSON files in '~/.openclaw/skills/orders/'. The 'clawtip' utility skill manages user tokens stored in 'configs/config.json' and handles complex multi-step payment flows (authorization, authentication, and polling) through detailed instructions in SKILL.md. All network communication is directed to legitimate JD.com endpoints (ms.jr.jd.com), and the use of local credential storage and external network access is explicitly disclosed and justified in IMPORTANT_STATEMENTS.md. No evidence of data exfiltration, malicious prompt injection, or unauthorized execution was found.