ClawAudit verdict
creator-feed-watch
YouTube video analysis tool that fetches public video data and maintains a local watchlist; transparent media monitoring with no unexpected data collection.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (5)
Possible hardcoded credential
README.md · code · api_key: "YOUR_YOUTUBE_DATA_API_KEY
<script> tag in markdown — potential code injection
test/index.test.js · prose · downgraded · <script>
Uses exec() — may execute shell commands
src/transcript.js · prose · downgraded · exec(
Popular HTTP library — network access
scripts/check-release.js · prose · downgraded · got
Accesses sensitive environment variables
src/youtube-api.js · prose · downgraded · process.env.YOUTUBE_API_KEY
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.