ClawAudit verdict
context-management
The skill manages context and uses network capabilities, but its behavior seems legitimate.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Findings (3)
References sudo โ requests elevated privileges
SKILL.md ยท code ยท sudo
Uses exec() โ may execute shell commands
references/operation-costs.md ยท prose ยท downgraded ยท exec (
References agent memory files
references/operation-costs.md ยท prose ยท downgraded ยท MEMORY.md
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_out Is this flag fair?
Thanks โ recorded.