ClawAudit verdict

molt-beach

moltbeach

88
๐ŸŸข Trusted
Low risk โ€” reviewed by ClawAudit, behavior matches stated purpose

Pixel art platform that purchases and animates grid pixels via API; file_write is for local state storage, and network access is to the documented moltbeach service for pixel claims.

โš  Flagged for review โ€” coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis โ€” not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

38
security
90
transparency
80
maintenance

Permission integrity

Makes network requests but does not declare curl/wget in required binaries

network_out

Performs file operations but does not declare file-accessing binaries

file_read+write

Findings (2)

Pattern match critical

Possible hardcoded credential

llms.txt ยท code ยท Secret: 'your-saved-secret

Pattern match medium

Accesses system credential store

skill.json ยท prose ยท downgraded ยท keychain

Permissions & capabilities

No declared permissions โ€” minimal attack surface.

network_outfile_write

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API