ClawAudit verdict
nfc-tools
The skill is for NFC tag management and does not show any malicious intent.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
References sudo โ requests elevated privileges
README.md ยท code ยท sudo
Writes to SKILL.md โ self-modifying skill
README.md ยท prose ยท downgraded ยท SKILL.md`) for discovery (`nfc-list`, `nfc-taginfo`), read flows (`nfc-ndefcat`,
Blob URL โ may embed executable content
references/fallback.md ยท prose ยท downgraded ยท blob:
Permissions & capabilities
No declared permissions โ minimal attack surface.
Is this flag fair?
Thanks โ recorded.