ClawAudit verdict
.mcp.json
design-researh
MCP server config spawns local processes
The skill has broad capabilities such as 'mcp_server_config' and 'env_access_declared', which could potentially be misused. However, the content seems to be focused on a legitimate purpose of performing design research.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but ClawAudit detects co-occurrence โ it does not verify that one flows into another. Read the code to confirm a live chain.
MCP server config spawns local processes โ commands run with user privileges
LLM06 ยท ASI02 ยท ASI03
Permissions & capabilities
Requires 1 environment variable. (1 sensitive: BRAVE_API_KEY). Requires 1 system binary.
mcp_server_configprocess_execenv_access_declared Thanks โ recorded.