ClawAudit verdict
ourgroceries
The skill provides instructions for interacting with OurGroceries.com to manage shopping lists and does not contain any malicious or deceptive behavior.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (4)
Possible hardcoded credential
lib/ourgroceries/__init__.py · prose · downgraded · PASSWORD = 'password
Python aiohttp session — async network access
lib/ourgroceries/__init__.py · prose · downgraded · aiohttp.ClientSession
Python os.getenv — reads environment variable
scripts/add_item.py · prose · downgraded · os.getenv(
Uses XMLHttpRequest — network access
scripts/devtools_network_monitor.js · prose · downgraded · XMLHttpRequest
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.