ClawAudit verdict

byted-viking-developer

88
🟢 Trusted
Low risk — reviewed by ClawAudit, behavior matches stated purpose

Viking SDK developer guide providing documentation and code examples for VikingDB, KnowledgeBase, and Memory SDK integration; purely instructional content with no malicious behavior.

⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

25
security
90
transparency
70
maintenance

Findings (8)

Pattern match high

Dynamic import() — loads module at runtime

resources/Viking 知识库/SDK参考/Go SDK/rerank 重排.md · code · import ( "

Pattern match medium

Python os.getenv — reads environment variable

resources/Viking 知识库/SDK参考/Python SDK/rerank 重排.md · code · os.getenv(

Pattern match medium

Python os.environ.get — reads environment variable

resources/Viking 记忆库/SDK参考/会话管理/添加会话-AddSession.md · code · os.environ.get(

Pattern match medium

References agent configuration files

resources/Viking 记忆库/最佳实践/打通 RTC 服务,在实时对话式 AI 中使用 Viking 长期记忆和知识库.md · code · AgentConfig

Pattern match medium

Long base64 string (100+ chars) — likely obfuscated payload

resources/VikingDB 向量库/SDK V2参考/Go SDK/数据面SDK/检索/检索后处理算子-PostProcess.md · prose · downgraded · PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHhtbG5zOnhsaW5rPSJodHRwOi8v

Pattern match medium

pip3 install — installs Python packages at runtime

resources/VikingDB 向量库/最佳实践/【向量库】多模态搜索实践(文搜图/图搜图) - API V2.md · code · pip3 install

Pattern match low

References agent memory files

resources/memory-python-sdk.md · prose · downgraded · Memory.md

Pattern match low

Python directory traversal

resources/VikingDB 向量库/最佳实践/【向量库】多模态搜索实践(文搜图/图搜图) - API V2.md · code · os.walk(

Why the tier is capped

Execution sink present in raw bytes (Hard Floor: class B). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.

Permissions & capabilities

No declared permissions — minimal attack surface.

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API