ClawAudit verdict
read-later-pro
The content accesses and uses various credentials and APIs, such as NANO_IMAGE_API_KEY, which could potentially be used to exfiltrate credentials.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Python urllib.request โ network access
scripts/extract_article.py ยท prose ยท downgraded ยท urllib.request
Python shutil file operation โ copies/moves/deletes files
scripts/manage_library.py ยท prose ยท downgraded ยท shutil.rmtree(
Permissions & capabilities
No declared permissions โ minimal attack surface.
credential_access Is this flag fair?
Thanks โ recorded.