ClawAudit verdict
ctf-osint
CTF OSINT reference skill covering public-source intelligence gathering for challenge competitions; all tools such as whois, shodan, and exiftool are standard research tools used on publicly available data.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
package_install
Findings (3)
Possible hardcoded credential
social-media.md ยท code ยท TOKEN="your_token
References SSH/GPG private keys
web-and-dns.md ยท code ยท ssh-key
Contains shortened/invite URL
web-and-dns.md ยท code ยท t.me/comrade404
Permissions & capabilities
No declared permissions โ minimal attack surface.
package_installnetwork_out Is this flag fair?
Thanks โ recorded.