ClawAudit verdict
repliz
The skill integrates with Repliz social media management API, requiring access to REPLIZ_ACCESS_KEY and REPLIZ_SECRET_KEY environment variables. While it seems legitimate, accessing credentials is a concern.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (1)
Instruction-prose smuggling shape detected: collects a sensitive target ("Secret") and emits it outward ("post"). Phrased as prose with no trigger tokens โ a semantic prompt-injection / data-exfil pattern the syntactic scanners can't see. Final tier capped at Caution; review the instructions before installing.
SKILL.md ยท To get your Access Key and Secret Key for Basic Authentication: 1. Navigate to https://repliz.com/user/setting/api 2. Generate or copy your **Access Key** and *
Permissions & capabilities
Requires 2 environment variables. (1 sensitive: REPLIZ_SECRET_KEY). Requires 1 system binary. (1 elevated: curl).
network_incredential_access Is this flag fair?
Thanks โ recorded.