Caveat verdict
clawpump-v2
grok-implement
Accesses credentials AND makes external network calls
This skill conducts real financial transactions on Solana mainnet, launching SPL tokens and executing trades signed by the user actual wallet, representing real financial risk.
Automated static analysis โ not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but Caveat detects co-occurrence โ it does not verify that one flows into another. Read the code to confirm a live chain.
Accesses credentials AND makes external network calls โ potential credential theft
LLM02 ยท ASI03
Accesses credentials AND encodes data โ may obfuscate stolen credentials
LLM02 ยท ASI03 ยท ASI04
Permission integrity
network_out
Findings (4)
Instructs covert action โ may act without user awareness
SKILL.md ยท prose ยท downgraded ยท silently
fetch() โ outbound network request
SKILL.md ยท code
Data encoding/decoding
SKILL.md ยท code
Makes HTTP request to external URL
SKILL.md ยท code ยท fetch("https://
Permissions & capabilities
Requires 1 environment variable.
data_encodingnetwork_outcredential_accessnetwork_in Thanks โ recorded.