Security audit
asr-hotwords
Security checks for vulnerabilities and agentic risk
Overview
The skill's code, instructions, and requirements are consistent with its stated purpose of mining hotwords from OpenClaw conversation history — but it reads and touches all agents' session files and will write/migrate files across workspaces and trigger automated agent injection, so review privacy and migration actions before installing.
This skill appears to do what it says (scan OpenClaw session logs, mine hotwords, export hotwords.md, and optionally inject them). Before installing: - Accept that the skill will read all agents' session files under ~/.openclaw/agents (sensitive/user data). Restrict config.yaml extract.agents if you want to limit scope. - Inspect ~/.openclaw/openclaw.json because the skill will read your LLM provider/apiKey/baseUrl to perform LLM calls — ensure those credentials are what you expect. - The migration script will copy historical vocab files into the new global skill dir and write MIGRATED.md into old skill directories; if you have private data in old skill directories, back it up first and review what will be moved. - The run pipeline uses the openclaw CLI to notify agents (openclaw gateway call agent) and instructs agents to call dmwork_management to inject voice-context; review that behavior and the exact message text — it says to run without notifying users. - Run initially in a controlled environment (limit agents list, run export-only to inspect outputs) and inspect hotwords.md before allowing any automated injection or scheduled runs. If you want, I can point out the exact lines in the files that perform the migration, session scanning, and agent notification so you can review them in place.
Static analysis
No suspicious patterns detected.
