ClawAudit verdict
aeo-system
The skill is designed for Answer Engine Optimization, focusing on auditing and improving AI assistant recommendations. It requires specific API keys but does not seem to handle sensitive data insecurely.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (5)
Possible hardcoded credential
README.md · code · API_KEY="your-key-here
<script> tag in markdown — potential code injection
templates/answer-hub-template.md · prose · downgraded · <script
Uses exec() — may execute shell commands
scripts/answer-intent-map.js · prose · downgraded · exec(
Node http/https module — low-level network access
scripts/answer-intent-map.js · prose · downgraded · require('https')
Accesses sensitive environment variables
scripts/answer-intent-map.js · prose · downgraded · process.env.PERPLEXITY_API_KEY
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.