Back to skill
Skillv0.1.2
Static analysis security
Claw Wiki · Deterministic local checks for risky code patterns and metadata mismatches.
Scanner verdict
SuspiciousApr 30, 2026, 5:12 AM
- Summary
- Detected: suspicious.destructive_delete_command, suspicious.exposed_secret_literal, suspicious.prompt_injection_instructions
- Reason codes
- suspicious.destructive_delete_commandsuspicious.exposed_secret_literalsuspicious.prompt_injection_instructions
- Engine
- v2.4.5
Evidence
warnopenclaw_docs/install/uninstall.md:56
Documentation contains a destructive delete command without an explicit confirmation gate.
suspicious.destructive_delete_command
warnopenclaw_docs/zh-CN/install/uninstall.md:63
Documentation contains a destructive delete command without an explicit confirmation gate.
suspicious.destructive_delete_command
criticalopenclaw_docs/brave-search.md:27
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/design/kilo-gateway-integration.md:136
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/gateway/configuration-reference.md:1614
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/gateway/remote.md:114
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/gateway/secrets-plan-contract.md:79
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/help/faq.md:1503
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/nodes/talk.md:58
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/providers/cloudflare-ai-gateway.md:16
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/providers/litellm.md:120
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/tools/firecrawl.md:29
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/tools/web.md:228
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/tts.md:101
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/zh-CN/brave-search.md:34
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/zh-CN/gateway/configuration.md:1570
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/zh-CN/help/faq.md:1277
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/zh-CN/nodes/talk.md:65
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/zh-CN/tools/firecrawl.md:36
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/zh-CN/tools/web.md:159
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
criticalopenclaw_docs/zh-CN/tts.md:94
Documentation appears to expose a hardcoded API secret or token.
suspicious.exposed_secret_literal
warnopenclaw_docs/channels/googlechat.md:186
Prompt-injection style instruction pattern detected.
suspicious.prompt_injection_instructions
warnopenclaw_docs/channels/group-messages.md:22
Prompt-injection style instruction pattern detected.
suspicious.prompt_injection_instructions
warnopenclaw_docs/concepts/memory.md:70
Prompt-injection style instruction pattern detected.
suspicious.prompt_injection_instructions
warnopenclaw_docs/date-time.md:65
Prompt-injection style instruction pattern detected.
suspicious.prompt_injection_instructions
warnopenclaw_docs/gateway/configuration-reference.md:166
Prompt-injection style instruction pattern detected.
suspicious.prompt_injection_instructions
warnopenclaw_docs/gateway/security/index.md:1118
Prompt-injection style instruction pattern detected.
suspicious.prompt_injection_instructions
warnopenclaw_docs/zh-CN/channels/discord.md:309
Prompt-injection style instruction pattern detected.
suspicious.prompt_injection_instructions
warnopenclaw_docs/zh-CN/channels/googlechat.md:187
Prompt-injection style instruction pattern detected.
suspicious.prompt_injection_instructions
warnopenclaw_docs/zh-CN/concepts/memory.md:58
Prompt-injection style instruction pattern detected.
suspicious.prompt_injection_instructions
warnopenclaw_docs/zh-CN/gateway/configuration.md:1052
Prompt-injection style instruction pattern detected.
suspicious.prompt_injection_instructions
