pamela-call

clawhub:pamela-call

View source
B
75/100

First Seen

Feb 18, 2026

Last Scanned

Feb 21, 2026

Findings

3

Score

75/100

CRITICAL 1
LOW 2

Findings (3)

CRITICAL
Text combines credential access with network transmission
L165

Text combines credential access with network transmission

Only credential required is your API key. For webhooks, always verify the X-Pamela-Signature header; see SDK docs for verification.
FIX

Remove the combination of credential access and network transmission from the tool. If the tool needs credentials, access them via a secrets manager and never transmit them externally.

FP?

Likely FP if the tool legitimately uses credentials for API authentication (e.g., reading an API key to make authenticated requests to the same service).

LOW
pip install arbitrary package
L34

Detects pip install of arbitrary packages that modify the host environment

pip install th
FIX

Pin all pip packages to exact versions (e.g., pip install package==1.2.3). Use a requirements.txt or pyproject.toml with pinned versions and hash verification.

FP?

Likely FP if the match is in documentation showing how to install the skill's own PyPI package.

LOW
Global package installation
L45

Detects global installation of packages which affects the host system

npm install -g @
FIX

Replace npm install -g with a local install (npm install --save-dev) or use npx with a pinned version. Global installs modify the system and risk supply chain attacks.

FP?

Likely FP if the global install is for a well-known CLI tool (e.g., typescript, eslint) in setup documentation, though the supply chain risk remains real.