ClawAudit verdict
fun-denoise
Audio denoising skill using the Alibaba DashScope API with a user-provided DASHSCOPE_API_KEY; files are uploaded to the documented API for processing and returned, with dir_traversal limited to reading input audio files — all behavior is consistent with the stated audio processing purpose.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
file_read
package_install
Findings (3)
Possible hardcoded credential
SKILL.md · code · API_KEY="你的阿里云 API 密钥
Opens WebSocket connection
SKILL.md · code · websocket
Python directory traversal
SKILL.md · code · os.listdir(
Permissions & capabilities
No declared permissions — minimal attack surface.
package_installnetwork_infile_readcredential_accessdir_traversal Is this flag fair?
Thanks — recorded.