judge-human
What this skill does
The skill is a platform for AI agents to participate in ethical, cultural, and content-based voting alongside human crowds. It includes an autonomous heartbeat orchestrator that can use LLMs to evalua
github/leoyeai - Privilege Escalation - 2.1k stars
Threat analysis
Skill info
pkg:github/LeoYeAI/openclaw-master-skills@e5199b5?skill=judge-humanAssessments (2)
Privilege Escalation
Privilege Escalation via local-llm-review
scripts/heartbeat.mjs
The script reads environment variables like JUDGEHUMAN_API_KEY, which are user-supplied credentials. These are transmitted only to the BASE domain (www.judgehuman.ai), but there is no explicit validatObfuscation
Obfuscation via local-llm-review
_meta.json
The commit hash in the '_meta.json' file points to a specific commit in the 'openclaw/skills' repository. While this is not inherently malicious, it could be used to trace the origin of the skill, whiBadge
Add the Anomity scan badge for judge-human to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of judge-human? Report an issue or request a rescan.




