ClawAudit verdict
modelscope-image
modelscope-img
The skill uses the ModelScope API to generate images based on user prompts. It requires an API key but does not exfiltrate or misuse credentials. The skill's behavior matches its stated purpose and does not exhibit malicious or deceptive behavior.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (1)
Python os.environ.get — reads environment variable
scripts/generate_qwen.py · prose · downgraded · os.environ.get(
Permissions & capabilities
No declared permissions — minimal attack surface.
credential_access Is this flag fair?
Thanks — recorded.