Back to skill

Security audit

growth-engineer

Security checks for vulnerabilities and agentic risk

Overview

This is a real growth automation skill, but it needs Review because it can install and update code, run on a schedule, and handle valuable credentials with several concrete security weaknesses.

Install only if you want a broad local growth-automation system, not a read-only advice prompt. Use a dedicated workspace and least-privileged OS/user account, disable or review self-update and recurring cron behavior if you need reproducible reviewed code, avoid the curl-to-bash ASC installer path, and prefer a keychain or secret manager over plaintext token files. Grant provider tokens the minimum read/write scopes needed and enable GitHub issue/PR creation only when you explicitly want the skill to mutate repository state.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/openclaw-growth-start.mjs:1348
Finding

Unpinned Remote Installer Is Downloaded and Executed Through a Shell

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/export-sentry-summary.mjs:380
Finding

Sentry Pagination Can Forward Bearer Tokens to an Attacker-Controlled Origin

Content
View full analysis
controller.abort(), timeoutMs); try { response = await fetch(url, { method: 'GET', signal: controller.signal, headers: { Accept: 'application/json', Authorization: `Bearer ${token}`, 'User-Agent': 'openclaw-growth-sentry-exporter', }, }); } catch (error) { lastError = isAbortError(error) ? new Error(`Sentry API request timed out after ${timeoutMs}ms`) : error; if (lastError && typeof lastError === 'object') { lastError.retryable = true; } if (attempt < DEFAULT_SENTRY_FETCH_RETRIES - 1) { await sleep(Math.min(1_000 * 2 ** attempt, 8_000)); continue; } throw lastError; } finally { clearTimeout(timeout); } const body = await response.text(); if (response.ok) { return body ? JSON.parse(body) : null; } lastError = new Error(`Sentry API ${response.status}: ${body.slice(0, 500) || 'request failed'}`); lastError.status = response.status; lastError.retryable = isRetryableSentryStatus(response.status); if (isRetryableSentryStatus(r ...[truncated 3839 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/openclaw-growth-start.mjs:1207
Finding

RevenueCat and Sentry Tokens Are Persisted in Plaintext Without Permission Hardening

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (589)

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

The generated secret-runner install script creates system users, writes executables into /usr/local/bin, migrates secrets, and installs sudoers rules granting passwordless execution as another user. This is a major privilege-boundary modification that can create durable escalation pathways if wrapper commands or downstream scripts are ever subverted.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The public description presents a growth-analysis skill, but the content authorizes software installation, shell-profile mutation, PATH changes, and local bootstrap behavior. This mismatch can mislead users and policy systems into granting trust or execution to a skill whose operational impact is much broader than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The public description presents a growth-analysis skill, but the content authorizes software installation, shell-profile mutation, PATH changes, and local bootstrap behavior. This mismatch can mislead users and policy systems into granting trust or execution to a skill whose operational impact is much broader than advertised.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
- Copied-runtime scripts under `scripts/openclaw-growth-*.mjs` remain the compatibility path for agents that install this as a plain `SKILL.md` folder

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

md
- The cron/system-event prompt must invoke `node scripts/openclaw-growth-runner.mjs --config <active-config> --state <active-config-dir>/state.json`. Do not let

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 310)May include surrounding context.

md
- The cron/system-event prompt must invoke `node scripts/openclaw-growth-runner.mjs --config <active-config> --state <active-config-dir>/state.json`. Do not let

Self-Modification

High
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill explicitly contemplates modifying itself directly for upstream fixes, which normalizes self-modification of trusted instructions. In agent systems, self-edit capability undermines auditability and can let a compromised or misrouted workflow alter future behavior persistently.

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

md
Treat this installed skill as vendor-managed and replaceable.
Agents should almost never edit this skill in-place for user- or project-specific customization, because future skill updates may overwrite local changes.
When the user wants custom behavior, create a separate companion skill or project-local customization skill instead, for example `openclaw-growth-custom`, and have that skill reference or layer on top of this one.
Only modify this skill directly when the change is intended as an upstream reusable fix for the canonical skill repository.

## Setup DX Rules

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The skill standardizes collecting and loading multiple high-value credentials from a local secrets.env file. While local secret storage can be appropriate, centralizing broad third-party tokens and instructing the runtime to auto-load them materially increases blast radius if the host, process, logs, or downstream tools are compromised.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

md
- After each setup phase, summarize only the result and the next concrete action.
- Keep secrets out of prompts, repo files, logs, and command arguments; prefer host-agent secret storage or environment injection.
- Never ask the user to paste API keys, GitHub tokens, or App Store Connect `.p8` private-key contents into Discord, OpenClaw chat, Hermes chat, GitHub issues, PRs, or any shared transcript. Chat is not an appropriate secret transport.
- For secrets, give a secure host-terminal path: set env vars in the runtime shell, an agent secret store, a password manager injection flow, or the wizard-managed `~/.config/openclaw-growth/secrets.env` with `chmod 600`. Growth commands must load that env file automatically. For ASC `.p8`, prefer asking for the local file path to Apple's original downloaded file name `AuthKey_<KEY_ID>.p8`; do not rename the file because the wizard derives the key id from that name. Pasted `.p8` content is only a fallback. Store only `ASC_PRIVATE_KEY_PATH` and never echo the private key back.
- When SDK instrumentation is missing or weak, guide the developer through the `analyticscli-ts-sdk` setup path so analytics events become useful for later growth analysis.
- If AnalyticsCLI has no default project and multiple projects are visible, do not report that as a hard error. List the available projects, ask the user which one to use, persist the choice with `openclaw start --config openclaw.config.json --project <project_id>` or `analyticscli projects select <project_id>`, and then retry the setup/run.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

md
node scripts/openclaw-growth-status.mjs --config data/openclaw-growth-engineer/config.json --json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 310)May include surrounding context.

md
node scripts/openclaw-growth-status.mjs --config data/openclaw-growth-engineer/config.json --json

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Instructing status commands to automatically load secrets into the process environment expands credential exposure to routines that may not strictly need all tokens. This increases the chance of accidental disclosure through subprocesses, debugging output, or compromise of auxiliary tooling.

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

bash
  node scripts/openclaw-growth-status.mjs --config data/openclaw-growth-engineer/config.json --json
  • The status command loads ~/.config/openclaw-growth/secrets.env, runs live connector checks, and treats GitHub code access separately from GitHub issue/PR delivery.
  • Do not require a single global GitHub repo for connector setup. GitHub is connected when auth/token is valid; choose or infer the repository per app/task later.
  • Answer from that command only. If it cannot be run, say "I have not run a connector status check yet" and give the wizard command; do not say credentials are missing just because they are not visible in chat.
  • Keep the answer short: say "Ja" only if every connector status is connected; otherwise list only the non-connected connector names and the status command's next action.

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The documented pattern has users manually edit a plaintext secrets file containing valuable API keys and paths to private keys. Even with restrictive permissions, plaintext secret files are a sensitive target and increase persistence of credential exposure on disk.

Content

Scanner excerpt · SKILL.md (reported line 340)May include surrounding context.

bash
  install -d -m 700 ~/.config/openclaw-growth
  umask 077
  $EDITOR ~/.config/openclaw-growth/secrets.env
  # add lines like:
  # REVENUECAT_API_KEY=...
  # ASC_KEY_ID=...

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

This continues the same secret-on-disk pattern and explicitly normalizes storage of several sensitive credentials in a file. The danger is compounded by the skill's broad automation and repeated command execution, which may load those secrets frequently.

Content

Scanner excerpt · SKILL.md (reported line 346)May include surrounding context.

ASC_KEY_ID=...

ASC_ISSUER_ID=...

ASC_PRIVATE_KEY_PATH=/home/lo/.config/openclaw-growth/AuthKey_XXXX.p8

chmod 600 ~/.config/openclaw-growth/secrets.env

text
- Good `.p8` pattern: keep Apple's original downloaded file name `AuthKey_<KEY_ID>.p8`, then paste only that local file path into the terminal wizard. Do not rename the file; the wizard derives `ASC_KEY_ID` / `ASC_BOOTSTRAP_KEY_ID` from the file name. Pasting the full `.p8` content is only a fallback when the file is not available on the host.
- OpenClaw Growth commands load the wizard-managed env file automatically; never put secrets in command-line args.

Credential Access

High
Category
Privilege Escalation
Confidence
92% confidence
Finding

The ASC setup flow involves multiple privileged API keys and local handling of .p8 private keys, with some values persisted via environment-based secret storage. This is inherently high risk because compromise of those credentials can expose app analytics, reports, and potentially broader App Store Connect data depending on granted roles.

Content

Scanner excerpt · SKILL.md (reported line 549)May include surrounding context.

md
- Say ASC setup uses two API keys: a Reports key with `Sales and Reports` for ongoing Growth Engineer downloads, plus a temporary Setup key with `Admin` used once to create the initial App Analytics report request. `Finance` or `Admin` also works for ongoing report downloads, but prefer `Sales and Reports` after bootstrap. Add `Customer Support` for App Store ratings/review text, `Developer` for builds/TestFlight/delivery status, and `App Manager` only when app metadata, pricing, or release settings are needed.
- Tell the user to copy `ASC_ISSUER_ID` from the API keys page, download both `.p8` files, keep Apple's original `AuthKey_<KEY_ID>.p8` file names, and paste the local file paths into the terminal wizard. Do not tell them to rename the `.p8`; the wizard derives `ASC_KEY_ID` and `ASC_BOOTSTRAP_KEY_ID` from the file names.
- Store only env vars/secrets: `ASC_KEY_ID`, `ASC_ISSUER_ID`, and `ASC_PRIVATE_KEY_PATH`; the wizard can still create the `.p8` file from validated pasted terminal content as a fallback. Never commit the `.p8` private key.
- The Setup Admin key is not saved to `secrets.env`. The wizard keeps the temporary secure `.p8` copy on the host and tells the user to revoke the Admin key in App Store Connect after setup.
- Do not ask for `ASC_APP_ID` upfront. After auth succeeds, ASC should use all accessible apps by default. Store an app filter only if the user explicitly asks to scope ASC to one app.
- After the key is present, run one read-only API-key `asc` smoke test before marking ASC connected. Do not check `asc web auth` and do not force a target app selection; default ASC analysis covers all accessible apps.
- Prefer `asc auth login` when the local `asc` CLI supports keychain storage; otherwise use runtime env injection.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 564)May include surrounding context.

md
- Use the direct Sentry API exporter as the canonical growth source: `node scripts/export-sentry-summary.mjs`.

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

The startup protocol mandates updating the skill before operation, creating a self-refresh path that can change future behavior on each run. Combined with unpinned package fetching, this materially increases persistence and supply-chain risk.

Content

Scanner excerpt · SKILL.md (reported line 617)May include surrounding context.

md
When the user says "start", "run", or "kick off" the skill:

1. Run the Dependency Refresh Protocol first. It must update this skill, the `analyticscli-cli` skill when available, and the `@analyticscli/cli` npm package, then verify `command -v analyticscli`.
2. If setup is incomplete, connectors are not selected, AnalyticsCLI auth is missing/invalid, or the host is Hermes, route the user to the bundled wizard before any preflight/start run.
   - In Hermes chat/Discord/non-interactive terminals, do not run the wizard yourself. Show the full command below and tell the user to paste it into the VPS/host shell.
   - Only run this command yourself when you are already operating inside an interactive user terminal that can safely receive secret input outside chat.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 661)May include surrounding context.

md
Use the legacy bootstrap-and-copy runtime only when the standalone CLI is unavailable in the target workspace.

## Output Rules

- max 3-5 proposals per pass
- each proposal must include measurable impact and file/module hypotheses

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The skill explicitly documents persisted secrets in a local secrets.env file and marks them as agent-readable via runtime secret resolution. In the context of an automation skill that also runs external commands and can create issues or PRs, this increases the blast radius of prompt injection, command abuse, or local file exfiltration because valuable API tokens are centrally stored and accessible to the runtime.

Content

Scanner excerpt · data/openclaw-growth-engineer/config.example.json (reported line 361)May include surrounding context.

json
"mode": "openclaw-secret-refs",
      "persisted": true,
      "agentReadable": "runtime_resolves_secret_refs",
      "secretsFile": "~/.config/openclaw-growth/secrets.env"
    }
  },
  "secrets": {

Self-Modification

High
Category
Rogue Agent
Confidence
97% confidence
Finding

The script contains a self-update path that forcibly updates the installed skill during bootstrap, which is a strong form of self-modification. In security terms this is dangerous because a local setup action can mutate the executing toolchain by pulling new code from an external source, bypassing normal review expectations and compounding supply-chain compromise impact.

Content

Scanner excerpt · scripts/bootstrap-openclaw-workspace.sh (reported line 87)May include surrounding context.

sh
WORKSPACE="$(cd "${SKILL_ROOT}/../.." && pwd)"
fi

if [[ ( "${skill_slug}" == "growth-engineer" || "${skill_slug}" == "openclaw-growth-engineer" ) && -f "${SKILL_ROOT}/.clawhub/origin.json" && "${OPENCLAW_GROWTH_DISABLE_SELF_UPDATE:-}" != "1" && "${OPENCLAW_GROWTH_BOOTSTRAP_SKIP_UPDATE:-}" != "1" ]]; then
  if command -v clawhub >/dev/null 2>&1; then
    (cd "${WORKSPACE}" && clawhub --no-input --dir skills update "${skill_slug}" --force) || true
  elif command -v npx >/dev/null 2>&1; then

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/discord-openclaw-bridge.mjs (reported line 80)May include surrounding context.

js
const token = process.env.DISCORD_BOT_TOKEN?.trim();
  if (!token) {
    throw new DiscordBridgeError(
      "DISCORD_BOT_TOKEN is required. Put it in .env or export it in your shell.",
    );
  }
  return token;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw-growth-wizard.mjs (reported line 3861)May include surrounding context.

js
const token = process.env.DISCORD_BOT_TOKEN?.trim();
  if (!token) {
    throw new DiscordBridgeError(
      "DISCORD_BOT_TOKEN is required. Put it in .env or export it in your shell.",
    );
  }
  return token;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw-growth-wizard.mjs (reported line 3871)May include surrounding context.

js
const token = process.env.DISCORD_BOT_TOKEN?.trim();
  if (!token) {
    throw new DiscordBridgeError(
      "DISCORD_BOT_TOKEN is required. Put it in .env or export it in your shell.",
    );
  }
  return token;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/openclaw-growth-wizard.mjs (reported line 3957)May include surrounding context.

js
const token = process.env.DISCORD_BOT_TOKEN?.trim();
  if (!token) {
    throw new DiscordBridgeError(
      "DISCORD_BOT_TOKEN is required. Put it in .env or export it in your shell.",
    );
  }
  return token;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/openclaw-growth-wizard.mts (reported line 4135)May include surrounding context.

text
const token = process.env.DISCORD_BOT_TOKEN?.trim();
  if (!token) {
    throw new DiscordBridgeError(
      "DISCORD_BOT_TOKEN is required. Put it in .env or export it in your shell.",
    );
  }
  return token;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/openclaw-growth-wizard.mts (reported line 4145)May include surrounding context.

text
const token = process.env.DISCORD_BOT_TOKEN?.trim();
  if (!token) {
    throw new DiscordBridgeError(
      "DISCORD_BOT_TOKEN is required. Put it in .env or export it in your shell.",
    );
  }
  return token;

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.potential_exfiltration

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/export-analytics-summary.mjs:106

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/export-asc-summary.mjs:188

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/openclaw-growth-preflight.mjs:290

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/openclaw-growth-runner.mjs:355

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/openclaw-growth-start.mjs:429

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/openclaw-growth-status.mjs:121

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/openclaw-growth-wizard.mjs:1950

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/export-analytics-summary.mts:110

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/export-asc-summary.mts:185

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/openclaw-growth-preflight.mts:295

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/openclaw-growth-runner.mts:432

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/openclaw-growth-start.mts:427

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/openclaw-growth-status.mts:133

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/openclaw-growth-wizard.mts:2118

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/asc-exporter-cache.test.mjs:82

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/bootstrap-heartbeat.test.mjs:12

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/connector-health-cadence.test.mjs:114

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/install-analyticscli-cli.test.mjs:54

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
tests/production-release-filter.test.mjs:65

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/export-asc-summary.mjs:50

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/export-coolify-summary.mjs:33

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/export-paddle-summary.mjs:51

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/export-revenuecat-summary.mjs:153

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/export-sentry-summary.mjs:29

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/export-seo-summary.mjs:70

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/openclaw-growth-engineer.mjs:1598

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/openclaw-growth-preflight.mjs:14

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/openclaw-growth-runner.mjs:320

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/openclaw-growth-start.mjs:16

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/openclaw-growth-status.mjs:35

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/openclaw-growth-wizard.mjs:19

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/export-asc-summary.mts:54

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/export-coolify-summary.mts:37

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/export-paddle-summary.mts:56

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/export-revenuecat-summary.mts:152

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/export-sentry-summary.mts:32

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/export-seo-summary.mts:75

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/openclaw-growth-engineer.mts:1707

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/openclaw-growth-preflight.mts:25

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/openclaw-growth-runner.mts:392

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/openclaw-growth-start.mts:31

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/openclaw-growth-status.mts:46

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/openclaw-growth-wizard.mts:34

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
scripts/export-asc-summary.mjs:315

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
scripts/openclaw-growth-preflight.mjs:556

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
scripts/openclaw-growth-start.mjs:509

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
scripts/openclaw-growth-status.mjs:239

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
src/export-asc-summary.mts:313

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
src/openclaw-growth-preflight.mts:594

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
src/openclaw-growth-start.mts:510

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
src/openclaw-growth-status.mts:264