bizcard
What this skill does
Business card scanner and Google Contacts manager
github/leoyeai - Exfiltration - 2.1k stars
Threat analysis
Skill info
pkg:github/LeoYeAI/openclaw-master-skills@e5199b5?skill=bizcardAssessments (3)
Exfiltration
Exfiltration via local-llm-review
templates/SOUL.md
The skill uses the MATON_API_KEY environment variable to search Google Contacts via an API call that sends the user's API key in the Authorization header. This is a potential exfiltration risk if the External API Dependency
External API Dependency via local-llm-review
templates/SOUL.md
The skill relies on the MATON_API_KEY for Google Contacts integration. If this API is not properly secured or if the key is leaked, it could lead to unauthorized access to the user's Google Contacts.Insecure Temporary Files
Insecure Temporary Files via local-llm-review
templates/SOUL.md
The skill creates temporary files in /tmp for image processing. While it states that these files are deleted after the pipeline completes, there is no explicit code shown to ensure this cleanup happenBadge
Add the Anomity scan badge for bizcard to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of bizcard? Report an issue or request a rescan.




