ClawAudit verdict
auto-spec
A spec-driven development assistant that generates behavioral contracts from user requirements or reverse-engineers them from existing code; outputs are presented in conversation by default with no file writing unless explicitly requested.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Instructs covert action โ may act without user awareness
evals/iteration-1/reverse-spec-module-level/with_skill/outputs/spec_output.md ยท prose ยท downgraded ยท silently
References agent configuration files
evals/iteration-1/reverse-spec-module-level/with_skill/outputs/spec_output.md ยท prose ยท downgraded ยท AgentConfig
Permissions & capabilities
No declared permissions โ minimal attack surface.
Is this flag fair?
Thanks โ recorded.