ClawAudit verdict
pyre-world
pyreworld
Handles sensitive Solana private keys and potentially executes system commands. The use of these capabilities is not clearly justified by its purpose.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (6)
Uses exec() — may execute shell commands
SKILL.md · code · exec(
Accesses process.env — reads environment variables
SKILL.md · code
Instructs covert action — may act without user awareness
SKILL.md · prose · downgraded · Secretly
Popular HTTP library — network access
audit_sdk.md · code · got
Dynamic import() — loads module at runtime
lib/kit/providers/mapper.provider.d.ts · prose · downgraded · import("
References tunneling service
lib/torchsdk/quotes.js · prose · downgraded · serveO
Permissions & capabilities
Requires 3 environment variables. (1 sensitive: name: SOLANA_PRIVATE_KEY).
process_execcredential_access Is this flag fair?
Thanks — recorded.