Fairness Auditor
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill's core functionality, as described in SKILL.md and implemented in scripts/audit.sh, appears benign, focusing on auditing a provably fair casino at agent.rollhub.com. However, the file RETRY_PUBLISH.txt contains a hardcoded CLAWHUB_TOKEN (clh_6McIsLBkCfql-bsonlCCQ9p_4eWUw6azM9dxeU53Hl0). This is a critical vulnerability, as this token could be used by an attacker to publish or update skills under the owner's ID, posing a significant supply chain risk for the OpenClaw platform.
