Sato Hub
← Sato Check

Sato Check · Package

openclaw

npm:openclaw · as of 2026-09-26

Does it take your key?
no evidence
Unknown — we could not read this version.
No evidence line on file for this question yet.
Does your key leave?
observed
Not observed — no planted key left during install and start-up, under our test conditions — code paths that only run later, or only on a trigger, are not covered.
We ran it with planted test keys and saw it.
Can it move funds on its own?
no evidence
Unknown — we could not read what it exposes.
No evidence line on file for this question yet.
What changed?
observed
No change in key, host or fund behaviour since the previous version.
We ran it with planted test keys and saw it.

Is this your project? Respond →Dispute this reading

Hosts contacted

HostWhenRoleEvidence
registry.npmjs.orginstallregistryobserved
Evidence (1 line)
  • observedO-hosts2026-09-25

    registry.npmjs.org was contacted during install (registry).

    sandbox:obs_c5cd1ef4c68d3688

Limits

  • The traced lane has not run on this version: tarball is 95336387 bytes, over the 15728640-byte cap
  • Traced analysis follows flows inside one module only; a key handed from one module to another is not followed.
  • Traced lane did not run: tarball is 95336387 bytes, over the 15728640-byte cap.
  • Key egress not observed during install and start-up, under our test conditions — code paths that only run later, or only on a trigger, are not covered.
  • No tool inventory was available, so fund actions were not read.
  • Sandbox: DNS queries made directly by the target are not logged; hosts are recorded from proxied HTTP(S) requests and CONNECTs..
  • Sandbox: Code that ignores HTTP(S)_PROXY has no route out of the sandbox, so its attempts are not captured..

A profile describes what we read and ran, with dates. It is not a safety rating, an audit or an endorsement, and "not found" is not "not there".

sato.custody/v1 · custody-1

Maintain this project? Respond to this reading

Loading sign-in…