ClawAudit verdict
review-responder
google-review-responder
The skill uses the Google Business Profile API to monitor reviews and draft responses, and it follows standard practices for usage. The skill's behavior matches its stated purpose, and it does not appear to have any malicious or deceptive behavior.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (4)
Possible hardcoded credential
get_client_token.py · prose · downgraded · SECRET = "YOUR_CLIENT_SECRET
References webhook/callback URL
SKILL.md · code · webhook_url
HTTP request to bare IP address — common in malicious payloads
oauth_server.py · prose · downgraded · http://123.45.67.89
Popular HTTP library — network access
SKILL.md · prose · downgraded · Got
Permissions & capabilities
No declared permissions — minimal attack surface.
network_in Is this flag fair?
Thanks — recorded.