ClawAudit verdict
ai-test-platform
Internal AI-powered test automation platform using DeepSeek/LangChain to generate and execute Pytest and Playwright scripts; executionSinkDetected reflects legitimate test script execution, not malicious behavior.
â Flagged for review â coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis â not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (6)
Possible hardcoded credential
project/backend/docs/EXECUTION_MODULE_SUMMARY.md ¡ code ¡ TOKEN="your_auth_token
Pipe to python â executes piped content as Python code
deploy/é¨ç˝˛ć楣.md ¡ prose ¡ downgraded ¡ | Python
References sudo â requests elevated privileges
deploy/é¨ç˝˛ć楣.md ¡ code ¡ sudo
subprocess execution â runs system commands from Python
project/backend/app/services/api_test_service.py ¡ prose ¡ downgraded ¡ subprocess.run(
Popular HTTP library â network access
project/frontend/docs/FRONTEND_SUMMARY.md ¡ code ¡ Axios
Dynamic import() â loads module at runtime
project/frontend/src/router/index.js ¡ prose ¡ downgraded ¡ import('
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution â cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
No declared permissions â minimal attack surface.
network_inpackage_install Is this flag fair?
Thanks â recorded.