Back to skill

Security audit

Edith Senso Knowledge

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do its stated job, but its setup asks users to give and persist a raw Senso API key in a voice-first smart-glasses workflow.

Review before installing. Use this only if you trust OpenClaw and Senso with your knowledge-base queries and possible document excerpts. Do not say an API key aloud; configure it through a protected secret or settings flow if available, use a limited Senso key, and rotate the key if it was spoken or pasted into chat history.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.