ClawAudit verdict
astroapi-skill
Calls a third-party astrology API using a user-provided API key via curl; the API call is transparent and matches the stated purpose of generating astrological charts.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Possible hardcoded credential
SKILL.md ยท code ยท API_KEY="your_token_here
Long base64 string (100+ chars) โ likely obfuscated payload
references/api-endpoints.md ยท prose ยท downgraded ยท identity/health/finance/career/love/relationships/creativity/spirituality/home/l
Permissions & capabilities
Requires 1 environment variable. (1 sensitive: ['ASTROLOGY_API_KEY']). Requires 1 system binary.
Is this flag fair?
Thanks โ recorded.