ClawAudit verdict
pagerunner-skill
Chrome browser automation using existing user sessions for legitimate browser control; focuses on safe interaction patterns with no credential exfiltration.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (5)
<script> tag in markdown — potential code injection
SECURITY.md · code · <script>
Accesses system credential store
SECURITY.md · prose · downgraded · Keychain
Opens WebSocket connection
ADVANCED.md · prose · downgraded · WebSocket
Makes HTTP request to external URL
EXAMPLES.md · code · fetch("https://
Base64 encoding/decoding
REFERENCE.md · prose · downgraded · Base64-encode
Permissions & capabilities
Requires 1 system binary.
package_installnetwork_in Is this flag fair?
Thanks — recorded.