captions

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Node.js script (scripts/tapi-auth.js) to handle account registration, email verification, and configuration updates.
  • [COMMAND_EXECUTION]: The authentication script modifies several shell profile files (such as .bashrc, .zshenv, .profile, and .zprofile) and PowerShell profiles to persist the TRANSCRIPT_API_KEY environment variable across sessions.
  • [COMMAND_EXECUTION]: The script updates the agent's local configuration files (e.g., .openclaw/openclaw.json) and user-level systemd environment settings to store and enable the service API key.
  • [EXTERNAL_DOWNLOADS]: The skill uses curl and the Node.js fetch API to interact with https://transcriptapi.com for account management and to retrieve transcript data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 02:59 AM