ClawAudit verdict

greek-compliance-aade

88
🟢 Trusted
Low risk — reviewed by ClawAudit, behavior matches stated purpose

Accesses system credential store AND makes external network calls

Greek tax compliance skill that explicitly requires human approval before any AADE/TAXIS submission, documents that credentials are only used when submitting to the government portal, and performs all calculation work offline — the AADE_PASSWORD usage is scoped to its stated purpose.

Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

0
security
90
transparency
90
maintenance

What it does

These are capability combinations: each listed behavior occurs in the skill, but ClawAudit detects co-occurrence — it does not verify that one flows into another. Read the code to confirm a live chain.

Capability combination critical

Accesses system credential store AND makes external network calls

LLM02 · ASI03

Findings (3)

Pattern match critical

Possible hardcoded credential

SKILL.md · code · PASSWORD="your-aade-password

Pattern match critical

Unicode homoglyph detected — uses lookalike characters to evade pattern matching

EVALS.json · prose

Pattern match high

References sudo — requests elevated privileges

SKILL.md · code · sudo

Permissions & capabilities

Requires 3 environment variables. (1 sensitive: AADE_PASSWORD). Requires 2 system binaries. (1 elevated: curl).

network_outcredential_store
Check another skill Browse the registry Auditing your own skills or configs? Use the API