ClawAudit verdict
atxswap
This skill manages an on-chain wallet (BSC/PancakeSwap V3) with real ATX/USDT swaps, liquidity operations, and ERC20 token transfers — elevated financial risk as errors could result in irreversible loss of funds, which is an unusual capability relative to typical agent skills.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (2)
Possible hardcoded credential
scripts/_helpers.js · prose · downgraded · password: ") {
if (args.password) return args.password;
Accesses system credential store
SKILL.md · prose · downgraded · Keychain
Permissions & capabilities
Requires 2 system binaries. (1 elevated: npm).
package_install Is this flag fair?
Thanks — recorded.