ClawAudit verdict
onchat
The skill allows users to interact with the OnChat protocol, reading and sending messages as blockchain transactions. It requires users to set environment variables for write operations, but it does not exhibit any malicious behavior.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (1)
Accesses sensitive environment variables
scripts/onchat.ts ยท prose ยท downgraded ยท process.env.ONCHAT_PRIVATE_KEY
Permissions & capabilities
No declared permissions โ minimal attack surface.
package_install Is this flag fair?
Thanks โ recorded.