Back to skill

Security audit

ClawMetry

Security checks for vulnerabilities and agentic risk

Overview

ClawMetry is a disclosed observability skill that collects sensitive agent telemetry for local dashboards and optional encrypted cloud sync.

Install only if you trust the `clawmetry` binary and are comfortable with an observability tool seeing agent transcripts, tool inputs and outputs, logs, memory files, and usage data. Keep cloud sync disabled unless you want remote access and accept encrypted telemetry being sent to ClawMetry Cloud.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill states that tool calls, parameters, results, message flow, and logs are collected, but it does not clearly and prominently warn that this telemetry can include sensitive session content when cloud sync is enabled. Even with claims of end-to-end encryption, users may unknowingly transmit secrets, prompts, personal data, or tool arguments off-host, creating privacy and compliance risk if sync is enabled without informed consent.

Static analysis

No suspicious patterns detected.