ClawAudit verdict
excel-data-import
Configuration-driven Excel/CSV import tool that reads and writes local files with field mapping and validation; no network access, no credential handling, behavior matches stated purpose.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (4)
Recursive delete from root or home — destructive command
references/troubleshooting.md · code · rm -rf /
Sets world-executable permissions
references/best-practices.md · code · chmod 700
pip3 install — installs Python packages at runtime
SKILL.md · prose · downgraded · pip3 install
Python directory traversal
assets/examples-archive/real-world/use-case-1.md · code · os.walk(
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.