ClawAudit verdict
agentbnb
The skill provides a legitimate method for finding, hiring, and serving specialist AI agents. It includes clear instructions for usage and emphasizes security considerations.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (5)
Possible hardcoded credential
bootstrap.test.ts · prose · downgraded · token: 'test-token
References child_process — can spawn system processes
bootstrap.ts · prose · downgraded · child_process
Dynamic import() — loads module at runtime
bootstrap.ts · prose · downgraded · import('
Opens WebSocket connection
bootstrap.ts · prose · downgraded · WebSocket
References agent configuration files
bootstrap.ts · prose · downgraded · agentConfig
Permissions & capabilities
Requires 1 system binary.
network_in Is this flag fair?
Thanks — recorded.