ClawAudit verdict
market-analysis
The skill sends data to a third-party server (http://8.145.54.67:3000/) for market analysis, which may raise privacy concerns.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Long base64 string (100+ chars) โ likely obfuscated payload
SKILL.md ยท frontmatter ยท YJa/S9VcfLFO3wYvntICzYD1+mP5yhXuA5LMqath6bE2bp6C86hFKUScxUmIy7SU8eN7rkonqPNWdQDI
HTTP request to bare IP address โ common in malicious payloads
SKILL.md ยท code ยท http://8.145.54.67
Permissions & capabilities
No declared permissions โ minimal attack surface.
Is this flag fair?
Thanks โ recorded.