ClawAudit verdict
blockbeats-to-chainthink
Content scraping and CMS publishing skill that fetches BlockBeats articles via browser and saves them as drafts to the user own ChainThink account using their own token; behavior is transparent and scoped to stated article-republishing purpose.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Findings (2)
Possible hardcoded credential
fetch.sh ยท prose ยท downgraded ยท TOKEN="eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJVVUlEIjoiY2Y3MzBlZWUtODU3YS00MWRl
Long base64 string (100+ chars) โ likely obfuscated payload
fetch.sh ยท prose ยท downgraded ยท eyJVVUlEIjoiY2Y3MzBlZWUtODU3YS00MWRlLTljM2EtNTMxODY5NDU0OTE5IiwiSUQiOjUxLCJVc2Vy
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_out Is this flag fair?
Thanks โ recorded.