ClawAudit verdict
AndonQ
andonq
Tencent Cloud smart customer service integration that authenticates via OAuth2 temporary codes stored locally with 0600 permissions and makes HTTPS calls only to declared Tencent Cloud endpoints; the credential handling and data flow are transparent and match the stated customer service purpose.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
subprocess execution — runs system commands from Python
scripts/check_env.py · prose · downgraded · subprocess.run(
Python urllib.request — network access
scripts/andon_sse_api.py · prose · downgraded · urllib.request
Popular HTTP library — network access
scripts/check_env.py · prose · downgraded · got
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
Requires 1 system binary.
Is this flag fair?
Thanks — recorded.