ClawAudit verdict
karakeep
karakeep-app
CLI for a self-hosted Karakeep bookmark manager; all network access is to the user's own instance via a user-provided API key, and operations are standard CRUD for bookmarks.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (1)
Possible hardcoded credential
SKILL.md ยท code ยท API_KEY="your-api-key
Permissions & capabilities
Requires 2 environment variables. (1 sensitive: KARAKEEP_API_KEY). Requires 1 system binary.
package_installnetwork_incredential_access Is this flag fair?
Thanks โ recorded.