ClawAudit verdict
netease-music-pusher
The skill interacts with the NetEase Music API, potentially sending user data to external hosts. However, this is for its intended purpose of providing music push functionality.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (2)
pip3 install โ installs Python packages at runtime
SKILL.md ยท code ยท pip3 install
Long base64 string (100+ chars) โ likely obfuscated payload
scripts/netease_client.py ยท prose ยท downgraded ยท 00e0b509f6259df8642dbc35662901477df22677ec152b5ff68ace615bb7b725152b3ab17a876aea
Permissions & capabilities
No declared permissions โ minimal attack surface.
package_install Is this flag fair?
Thanks โ recorded.