ClawAudit verdict
报价单工作流
quotation-workflow
The skill generates professional quotations in various formats (Excel, Word, HTML, PDF) with built-in data validation to prevent example or placeholder data from being used.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (6)
References sudo — requests elevated privileges
docs/PDF_EXPORT.md · code · sudo
apt-get install — installs system packages
docs/PDF_EXPORT.md · code · apt-get install
<script> tag in markdown — potential code injection
scripts/generate_quotation_html.py · prose · downgraded · <script
Python os.environ.get — reads environment variable
P0-REVISE-REPORT.md · code · os.environ.get(
References agent memory files
RETRO-2026-03-27.md · prose · downgraded · MEMORY.md
pip3 install — installs Python packages at runtime
scripts/add-pdf-pagenumbers.py · prose · downgraded · pip3 install
Permissions & capabilities
Requires 2 system binaries.
Is this flag fair?
Thanks — recorded.