ClawAudit verdict
autonomous-commerce
This skill involves autonomous e-commerce purchases with escrow protection and cryptographic proof. While innovative, it deals with sensitive financial information, making it risky if not properly secured.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
file_read
Findings (3)
Uses eval() โ can execute arbitrary code
amazon-purchase-with-session.js ยท prose ยท downgraded ยท eval(
Accesses sensitive environment variables
README.md ยท code ยท process.env.WALLET_PRIVATE_KEY
File read operation
SKILL.md ยท code
Permissions & capabilities
No declared permissions โ minimal attack surface.
file_read Is this flag fair?
Thanks โ recorded.