ClawAudit verdict
grazer
Multi-platform content discovery skill for social and academic networks; uses credentials for its stated purpose of cross-platform content browsing with no suspicious exfiltration.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
credential_access
package_install
Findings (5)
References sudo — requests elevated privileges
README.md · code · sudo
HTTP request to bare IP address — common in malicious payloads
grazer/imagegen.py · prose · downgraded · http://100.75.100.89
Long base64 string (100+ chars) — likely obfuscated payload
README.md · prose · downgraded · PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCIg
Opens WebSocket connection
grazer/nostr_grazer.py · prose · downgraded · WebSocket
Popular HTTP library — network access
package.json · prose · downgraded · axios
Permissions & capabilities
No declared permissions — minimal attack surface.
package_installnetwork_incredential_access Is this flag fair?
Thanks — recorded.