ClawAudit verdict
news-agent-v2
news-agent-v2-0
The skill is a news aggregator that collects and pushes news articles to messaging channels. It does not appear to have any malicious or deceptive behavior.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Long base64 string (100+ chars) — likely obfuscated payload
config.md · frontmatter · 3046022100a25aba0c967521267c6fce8056df0e75d9393ec1d99308bdf05630247d33b6f7022100
<script> tag in markdown — potential code injection
generate_html.py · prose · downgraded · <script>
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.