ClawAudit verdict
context-optimizer
Advanced context management library for token pruning and archival; all processing is local and network_in is only for npm package installation.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Recursive delete from root or home โ destructive command
INSTALL.md ยท code ยท rm -rf /
Dynamic import() โ loads module at runtime
lib/index.js ยท prose ยท downgraded ยท import('
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_in Is this flag fair?
Thanks โ recorded.