ClawAudit verdict
iqc-python-tree
This skill is an industrial-grade IQC control plan parsing engine that seems to be designed for legitimate industrial use cases, with no apparent malicious behavior.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (4)
Possible hardcoded credential
scripts/jwt_token.py · prose · downgraded · PASSWORD = "kang123456
HTTP request to bare IP address — common in malicious payloads
scripts/data_submit.py · prose · downgraded · http://192.168.60.241
Python shutil file operation — copies/moves/deletes files
scripts/csv_to_json.py · prose · downgraded · shutil.move(
importlib.import_module — dynamic module loading
scripts/preprocess_excel.py · prose · downgraded · importlib.import_module(
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.