ClawAudit verdict
musashi
The skill analyzes tokens using a conviction-weighted pipeline, with no indication of malicious behavior.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Possible hardcoded credential
scripts/gate_check.sh ยท prose ยท downgraded ยท TOKEN="${1:?Usage: gate_check.sh <token_address> [chain_id]}
Instructs covert action โ may act without user awareness
references/PATTERNS.md ยท prose ยท downgraded ยท quietly
Permissions & capabilities
Requires 3 environment variables. Requires 1 system binary.
Is this flag fair?
Thanks โ recorded.