ClawAudit verdict
aim-trade-news
The skill fetches and summarizes trade news from various sources. It does not contain any malicious code and seems to follow secure coding practices. It relies on an external API for data, which is a normal behavior for such a skill.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Pipe to python — executes piped content as Python code
SKILL.md · prose · downgraded · | Python
Python os.environ.get — reads environment variable
scripts/search_news.py · prose · downgraded · os.environ.get(
Permissions & capabilities
Requires 1 system binary.
Is this flag fair?
Thanks — recorded.