Caveat verdict
astronclaw-code-review
Accesses credentials AND writes files
A code review assistant for the AstronClaw platform that reads code files and generates quality/security/performance reports; all file access and API calls (iFlytek Spark) serve the stated review purpose transparently.
Automated static analysis — not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but Caveat detects co-occurrence — it does not verify that one flows into another. Read the code to confirm a live chain.
Accesses credentials AND writes files — may persist stolen credentials locally
LLM02 · LLM06 · ASI03
Both reads and writes files — verify scope is limited to intended directories
LLM06 · ASI02
Permission integrity
file_read+write
credential_access
package_install
Findings (4)
Possible hardcoded credential
SKILL.md · code · apiKey = "sk_live_1234567890
Uses eval() — can execute arbitrary code
src/tools/analyzers/security-analyzer.js · prose · downgraded · eval(
Dynamic import() — loads module at runtime
src/tools/code-quality-scanner.js · prose · downgraded · import('
File read operation
SKILL.md · code
Permissions & capabilities
No declared permissions — minimal attack surface.
package_installfile_writecredential_accessfile_readdir_traversal Thanks — recorded.