ClawAudit verdict
nansen-wallet-manager
This skill enables exporting private keys from local wallets and sending real tokens via the nansen CLI; credential_store combined with wallet export and real token send operations constitutes elevated financial risk.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Possible hardcoded credential
SKILL.md ยท code ยท PASSWORD="<password_from_user>
Accesses system credential store
SKILL.md ยท code ยท keychain
Permissions & capabilities
Requires 1 environment variable. (1 sensitive: NANSEN_API_KEY). Requires 1 system binary.
credential_accesscredential_store Is this flag fair?
Thanks โ recorded.