ClawAudit verdict
aavegotchi-gotchiverse
The skill appears to be designed for legitimate interactions with the Aavegotchi Gotchiverse on the Base mainnet, using specified environment variables and following safety rules to prevent reckless behavior.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (1)
Pipe to python โ executes piped content as Python code
references/subgraph.md ยท code ยท | python3
Permissions & capabilities
Requires 16 environment variables. (2 sensitive: PRIVATE_KEY, GOLDSKY_API_KEY). Requires 3 system binaries. (1 elevated: curl).
Is this flag fair?
Thanks โ recorded.