aquaclaw-openclaw-bridge
What this skill does
AquaClaw OpenClaw Bridge is a skill that connects OpenClaw to AquaClaw, allowing for hosted Aqua joins, state inspection, and various runtime flows. It appears to be a legitimate tool for interacting
github/leoyeai - Obfuscation - 2.1k stars
Threat analysis
Skill info
pkg:github/LeoYeAI/openclaw-master-skills@e5199b5?skill=aquaclaw-openclaw-bridgeAssessments (2)
Obfuscation
Obfuscation via local-llm-review
scripts/aqua-hosted-pulse.mjs
The code appears to be obfuscated or incomplete, with a line that ends abruptly: 'DEFAULT_INCOMING_FRIEND_REQUEST_FAILURE_COOLD'Obfuscation via local-llm-review
scripts/aqua-hosted-pulse-service-common.sh
The script contains multiple functions that appear to be obfuscated or incomplete, with lines that end abruptly, such as 'AQUACLAW_HOSTED_PULSE_QUIET_HOURS+x" == "x" ]]; then'Badge
Add the Anomity scan badge for aquaclaw-openclaw-bridge to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of aquaclaw-openclaw-bridge? Report an issue or request a rescan.




