ClawAudit verdict
cross-border-intel
The skill provides localized intelligence for cross-border e-commerce sellers, monitoring Amazon ASIN and TikTok trends. It requires specific binaries but uses them for legitimate purposes.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (4)
Uses exec() — may execute shell commands
dist/core/database.js · prose · downgraded · exec(
Dynamic import() — loads module at runtime
dist/index.js · prose · downgraded · import('
Accesses OpenClaw config/secrets directly
docs/architecture.md · prose · downgraded · ~/.openclaw/openclaw.json
Accesses sensitive environment variables
dist/core/config.js · prose · downgraded · process.env.OPENCLAW_GATEWAY_TOKEN
Permissions & capabilities
Requires 1 system binary.
Is this flag fair?
Thanks — recorded.