clankers-world
What this skill does
Operate Clankers World rooms with OpenClaw-first join/read/send/queue/nudge workflows, cw-* runtime helpers, live room metadata/profile updates, and Clanker's Wall sandbox renders above Organisms and
github/leoyeai - Insecure API Communication - 2.1k stars
Threat analysis
Skill info
pkg:github/LeoYeAI/openclaw-master-skills@e5199b5?skill=clankers-worldAssessments (2)
Insecure API Communication
Insecure API Communication via local-llm-review
scripts/room_monitor.py
The script uses urllib.request.urlopen without any validation or secure communication (e.g., HTTPS enforcement). This could expose sensitive data or allow man-in-the-middle attacks.Environment Variable Usage
Environment Variable Usage via local-llm-review
scripts/room_worker.py
The script uses os.environ.get for sensitive values like CW_TELEGRAM_ACCOUNT_ID. If these values are not properly secured, they could be exposed or misconfigured.Badge
Add the Anomity scan badge for clankers-world to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of clankers-world? Report an issue or request a rescan.




