ClawAudit verdict
Qwen 方言语音识别
asr-skill
A local speech recognition skill using Qwen3-ASR running on the user machine; the skill explicitly states no data is uploaded to third parties.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (5)
Recursive delete from root or home — destructive command
INSTALL.md · code · rm -rf ~
References child_process — can spawn system processes
package.js · prose · downgraded · child_process
Popular HTTP library — network access
README.md · code · axios
POSTs data to external URL
README.md · code · .post('http://
Accesses sensitive environment variables
index.js · prose · downgraded · process.env.MAX_NEW_TOKEN
Permissions & capabilities
Requires 5 environment variables. Requires 2 system binaries.
package_install Is this flag fair?
Thanks — recorded.