ClawAudit verdict

auto-dev

88
🟢 Trusted
Low risk — reviewed by ClawAudit, behavior matches stated purpose

API documentation and SDK reference skill for Auto.dev automotive data; network access is for calling the legitimate Auto.dev API, credential_access for an optional API key as documented.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

10
security
100
transparency
90
maintenance

Findings (7)

Pattern match critical

Possible hardcoded credential

README.md · code · API_KEY="sk_ad_your_key_here

Pattern match medium

Accesses sensitive environment variables

code-patterns.md · code · process.env.AUTODEV_API_KEY

Pattern match medium

Python os.environ.get — reads environment variable

code-patterns.md · code · os.environ.get(

Pattern match medium

Instructs covert action — may act without user awareness

error-recovery.md · prose · downgraded · silently

Pattern match medium

References webhook/callback URL

integration-recipes.md · code · WEBHOOK_URL

Pattern match medium

Long base64 string (100+ chars) — likely obfuscated payload

pricing.md · prose · downgraded · 2FJ0xrcWB3JyknZ2p3YWB3VnF8aWAnPydhYGNkcGlxJykndnBndmZ3bHVxbGprUGtsdHBga2B2dkBrZG

Pattern match medium

Accesses shell history/config

README.md · prose · downgraded · ~/.zshrc

Permissions & capabilities

No declared permissions — minimal attack surface.

data_encodingnetwork_in

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API