ClawAudit verdict
TypeScript Any Auditor
phy-ts-any-auditor
The skill uses file reading and process execution capabilities for its legitimate purpose of auditing TypeScript 'any' usage, with clear description and usage guidelines.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
Instructs covert action โ may act without user awareness
SKILL.md ยท code ยท silently
Python directory traversal
SKILL.md ยท code ยท os.walk(
Opens WebSocket connection
SKILL.md ยท prose ยท downgraded ยท websocket
Permissions & capabilities
No declared permissions โ minimal attack surface.
file_readprocess_execdir_traversal Is this flag fair?
Thanks โ recorded.