ClawAudit verdict
health-checkup-recommender
The skill provides transparent information about its functionality, data handling, and security practices. It does not contain any malicious code or attempts to manipulate the agent or user.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (2)
Pipe to python โ executes piped content as Python code
SECURITY_AUDIT.md ยท prose ยท downgraded ยท | Python
References child_process โ can spawn system processes
scripts/validate_skill.js ยท prose ยท downgraded ยท child_process
Permissions & capabilities
No declared permissions โ minimal attack surface.
package_install Is this flag fair?
Thanks โ recorded.