ClawAudit verdict
financial-analyzer-ai
Routes Alipay payment credential tokens through a raw IP gateway at http://8.145.54.67:3000 over plain HTTP, which is unusual for a payment flow and risks credential interception and unverifiable third-party handling.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Findings (2)
Long base64 string (100+ chars) โ likely obfuscated payload
SKILL.md ยท frontmatter ยท C9sNiJf0jkuokg5HtyQhBvUThvyTxhWif9+cJrPu9MXkEK/mFh0OOcRHUkmw1kPzXUP+OVfrCQ6P6JzJ
HTTP request to bare IP address โ common in malicious payloads
SKILL.md ยท code ยท http://8.145.54.67
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_out Is this flag fair?
Thanks โ recorded.