ClawAudit verdict
Prediction Stack Setup
prediction-stack-setup
The setup wizard configures cron-based autonomous market scanning and trade alert jobs using Anthropic API keys, Kalshi trading credentials, and iMessage delivery, wiring a trading system that operates without per-action user approval.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
credential_access
Findings (4)
Possible hardcoded credential
SKILL.md ยท code ยท API_KEY="sk-ant-...
Instructs covert action โ may act without user awareness
SKILL.md ยท code ยท silently
Python os.getenv โ reads environment variable
references/validation-troubleshooting.md ยท code ยท os.getenv(
POSTs data to external URL
scripts/validate_setup.py ยท prose ยท downgraded ยท .post(
"http://
Permissions & capabilities
No declared permissions โ minimal attack surface.
credential_accessnetwork_in Is this flag fair?
Thanks โ recorded.