ClawAudit verdict
fleece
Credit card research CLI using Brave Search for live data with a local spending profile; credential_access is for the user's own API key and local database.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
credential_access
package_install
Findings (4)
Pipe to python — executes piped content as Python code
plan.md · code · | python
Instructs covert action — may act without user awareness
pages/my_credit_cards.py · prose · downgraded · Silently
Python os.getenv — reads environment variable
cli.py · prose · downgraded · os.getenv(
importlib.import_module — dynamic module loading
test_fleece.py · prose · downgraded · importlib.import_module(
Permissions & capabilities
No declared permissions — minimal attack surface.
credential_accesspackage_install Is this flag fair?
Thanks — recorded.