Security audit
Oraclaw Calibrate
Security checks for vulnerabilities and agentic risk
Overview
This skill is a straightforward forecasting-calibration helper that asks for an API key and discloses per-call pricing, with no hidden execution or persistence found.
Install if you are comfortable giving OraClaw its API key and with the disclosed usage pricing. Avoid sending sensitive proprietary forecasts unless the service is acceptable for that data.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
