ClawAudit verdict
moltx-skills
The skill involves understanding MoltX and participating in various roles. It requires node binary and has specific environment requirements, which could be risky if not handled properly.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (4)
Possible hardcoded credential
runtime/src/tools/config.ts · prose · downgraded · API_KEY = "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJzdXBhYmFzZSIsInJlZiI6
Long base64 string (100+ chars) — likely obfuscated payload
runtime/src/contracts/MoltXCouncil.json · prose · downgraded · 0x60a080604052346100e65760017f9b779b17422d0df92223018b32b4d1fa46e071723d6817e248
Instructs covert action — may act without user awareness
runtime/src/tools/api.ts · prose · downgraded · silently
Dynamic import() — loads module at runtime
runtime/test/cli-surface.test.ts · prose · downgraded · import("
Permissions & capabilities
Requires 1 system binary.
package_install Is this flag fair?
Thanks — recorded.