ClawAudit verdict
notice-monitor
The skill involves monitoring URLs and sending notifications, which could potentially be used for scraping or excessive requests, but it seems to require user configuration and does not directly exfiltrate data.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
References child_process โ can spawn system processes
src/monitor.js ยท prose ยท downgraded ยท child_process
setuid โ privilege escalation mechanism
src/monitor.js ยท prose ยท downgraded ยท setuid
Popular HTTP library โ network access
package-lock.json ยท prose ยท downgraded ยท node-fetch
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class D). Final tier capped at Caution โ cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
No declared permissions โ minimal attack surface.
network_in Is this flag fair?
Thanks โ recorded.