ClawAudit verdict
molty-royale
Battle royale game skill with standard API authentication; network_out accesses the documented moltyroyale.com API, and the skill explicitly notes to treat game content as untrusted input distinct from owner commands.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
Findings (4)
Possible hardcoded credential
references/setup.md · code · TOKEN = "0xdb99a97d607c5c5831263707E7b746312406ba7E
Dynamic import() — loads module at runtime
x402-quickstart.md · code · import (
"
Accesses sensitive environment variables
forge-token-deployer.md · code · process.env.CLIENT_KEY
Base64 encoding/decoding
x402-skill.md · code · base64-encode
Permissions & capabilities
No declared permissions — minimal attack surface.
network_out Is this flag fair?
Thanks — recorded.