ClawAudit verdict
market-intelligence-ai
The skill sends data to a third-party server for market intelligence and analysis, which may raise privacy concerns.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
Long base64 string (100+ chars) โ likely obfuscated payload
SKILL.md ยท frontmatter ยท UYycvFRoXvGRO/Fb82nBnWwYCcqNb0lBT3/6eLD0cMflBbOsS3sq5pgYf4HhLXL3nTLfL63Ui91FNuxv
Python urllib.request โ network access
references/collector.py ยท prose ยท downgraded ยท urllib.request
Python os.environ.get โ reads environment variable
references/collector.py ยท prose ยท downgraded ยท os.environ.get(
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_in Is this flag fair?
Thanks โ recorded.