ClawAudit verdict
jarvis-voice
The skill uses sherpa-onnx TTS for offline text-to-speech and ffmpeg for audio processing, with no malicious or deceptive behavior detected.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
Uses exec() โ may execute shell commands
SKILL.md ยท code ยท exec(
Instructs covert action โ may act without user awareness
SKILL.md ยท prose ยท downgraded ยท quietly
Popular HTTP library โ network access
templates/HUMOR.md ยท prose ยท downgraded ยท got
Permissions & capabilities
No declared permissions โ minimal attack surface.
process_exec Is this flag fair?
Thanks โ recorded.