ClawAudit verdict
Discover
discover
The skill is designed for discovering new ideas, sources, opportunities, and angles. It uses memory capabilities for its legitimate purpose and does not show any suspicious behavior.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
agent_memory
Findings (3)
References agent memory files
SKILL.md ยท code ยท memory.md
Instructs covert action โ may act without user awareness
setup.md ยท prose ยท downgraded ยท quietly
Sets world-executable permissions
setup.md ยท code ยท chmod 700
Permissions & capabilities
No declared permissions โ minimal attack surface.
agent_memory Is this flag fair?
Thanks โ recorded.