ClawAudit verdict
Travel Search Flight Train Scenery - 旅行搜索 航班 火车 景点
jisu-travel
Travel search aggregator (flights, trains, scenery) using jisuapi.com with user-supplied key; pip install of requests/beautifulsoup4 is standard and declared; behavior matches stated purpose.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (3)
Possible hardcoded credential
SKILL.md · code · API_KEY="your_appkey_here
Popular HTTP library — network access
airport.md · prose · downgraded · GOT
Python os.getenv — reads environment variable
search.py · prose · downgraded · os.getenv(
Permissions & capabilities
Requires 1 environment variable. (1 sensitive: JISU_API_KEY). Requires 1 system binary.
package_install Is this flag fair?
Thanks — recorded.