ClawAudit verdict
Binance API
binance
The skill operates Binance APIs securely, handling signed requests, rate limits, and testnet execution. It seems to be a legitimate tool for interacting with Binance.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
agent_memory
Findings (4)
Opens WebSocket connection
SKILL.md · frontmatter · WebSocket
References agent memory files
SKILL.md · code · memory.md
Accesses sensitive environment variables
sdk-cli.md · code · process.env.BINANCE_API_KEY
Sets world-executable permissions
setup.md · code · chmod 700
Permissions & capabilities
Requires 2 environment variables. (2 sensitive: BINANCE_API_KEY, BINANCE_API_SECRET). Requires 3 system binaries. (1 elevated: curl).
agent_memory Is this flag fair?
Thanks — recorded.