ClawAudit verdict
api_ingestion_connectors
api-ingestion-connectors
A legitimate ETL/data-ingestion documentation skill for connecting to REST/GraphQL APIs and transforming responses into graph-ready structures; all credential handling uses environment variables appropriately.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
credential_access
Findings (2)
Pipe to python โ executes piped content as Python code
README.md ยท prose ยท downgraded ยท | Python
Possible hardcoded credential
scripts/api_connector.py ยท prose ยท downgraded ยท token="your_token_here
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_incredential_access Is this flag fair?
Thanks โ recorded.