ClawAudit verdict
api-monitor-dashboard
A minimal API monitoring and alerting dashboard skill that checks endpoint health and sends notifications via standard channels (Email/Slack); behavior matches stated purpose with no suspicious elements.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
<script> tag in markdown โ potential code injection
monitor.sh ยท prose ยท downgraded ยท <script>
Node http/https module โ low-level network access
monitor.sh ยท prose ยท downgraded ยท require('http')
Permissions & capabilities
No declared permissions โ minimal attack surface.
Is this flag fair?
Thanks โ recorded.