ClawAudit verdict
molt-beach
moltbeach
Pixel art platform that purchases and animates grid pixels via API; file_write is for local state storage, and network access is to the documented moltbeach service for pixel claims.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
file_read+write
Findings (2)
Possible hardcoded credential
llms.txt ยท code ยท Secret: 'your-saved-secret
Accesses system credential store
skill.json ยท prose ยท downgraded ยท keychain
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_outfile_write Is this flag fair?
Thanks โ recorded.