ClawAudit verdict
openalgo-executor
The skill interacts with the OpenAlgo API for trading operations, with no evidence of malicious behavior or capability misuse.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
References tunneling service
SKILL.md ยท frontmatter ยท ngrok
HTTP request to bare IP address โ common in malicious payloads
scripts/openalgo_client.py ยท prose ยท downgraded ยท http://100.66.165.107
Permissions & capabilities
No declared permissions โ minimal attack surface.
Is this flag fair?
Thanks โ recorded.