ClawAudit verdict
mindstudio-to-api-custom-function-builder
Code generation skill that produces MindStudio function templates; all network capabilities would be in the generated code for the target API, not the skill itself, which only generates JavaScript.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Findings (5)
Possible hardcoded credential
SKILL.md · code · apiKey: "your-api-key-here
<script> tag in markdown — potential code injection
README.md · prose · downgraded · <script
Pipe to python — executes piped content as Python code
README.md · prose · downgraded · | Python
fetch() — outbound network request
SKILL.md · code
Base64 encode (btoa) — may obfuscate data exfiltration
SKILL.md · prose · downgraded · btoa(
Permissions & capabilities
No declared permissions — minimal attack surface.
network_outnetwork_incredential_access Is this flag fair?
Thanks — recorded.