ClawAudit verdict
kairoa-toolkit
Installs packages AND executes processes
Launches a local Kairoa desktop application and opens specific tools via kairoa:// deep links; process_exec is used only to invoke the user's own installed app.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but ClawAudit detects co-occurrence โ it does not verify that one flows into another. Read the code to confirm a live chain.
Installs packages AND executes processes โ opaque dependency chain with execution
LLM03 ยท ASI04
Permission integrity
package_install
Findings (2)
subprocess execution โ runs system commands from Python
SKILL.md ยท code ยท subprocess.run(
Opens WebSocket connection
SKILL.md ยท prose ยท downgraded ยท WebSocket
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution โ cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
No declared permissions โ minimal attack surface.
data_encodingprocess_execpackage_install Thanks โ recorded.