ClawAudit verdict
omni
omni-master
A multi-domain routing skill delegating to domain-specific reference files; the content describes a cognitive routing architecture with no exfiltration, deception, or malicious patterns.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (7)
References sudo — requests elevated privileges
references/brain.md · code · sudo
Pipe to python — executes piped content as Python code
references/documents.md · prose · downgraded · | python
Changes file ownership
references/brain.md · code · chown
References SSH/GPG private keys
references/network-cloud.md · prose · downgraded · ssh-key
Accesses .ssh directory
references/network-cloud.md · prose · downgraded · .ssh/
Opens WebSocket connection
references/realtime.md · code · WebSocket
Sets world-executable permissions
references/system-admin.md · code · chmod 755
Why the tier is capped
Execution sink present in raw bytes (Hard Floor: class B). Final tier capped at Caution — cannot be lifted by any downgrade, example-payload opt-in, or allowlist.
Permissions & capabilities
No declared permissions — minimal attack surface.
network_in Is this flag fair?
Thanks — recorded.