ClawAudit verdict

rstack

resolved-sh-rstack

88
๐ŸŸข Trusted
Low risk โ€” reviewed by ClawAudit, behavior matches stated purpose

Operator toolkit for managing a resolved.sh presence using RESOLVED_SH_API_KEY to publish pages and register paid service endpoints on the user's own account; all operations are transparently scoped to the user's own resolved.sh resources.

โš  Flagged for review โ€” coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis โ€” not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

30
security
70
transparency
70
maintenance

Findings (3)

Pattern match critical

Pipe to python โ€” executes piped content as Python code

rstack-audit/SKILL.md ยท code ยท | python3

Pattern match critical

Possible hardcoded credential

rstack-services/SKILL.md ยท code ยท SECRET = "{webhook_secret from response}

Pattern match medium

Accesses sensitive environment variables

rstack-services/SKILL.md ยท code ยท process.env.WEBHOOK_SECRET

Permissions & capabilities

No declared permissions โ€” minimal attack surface.

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API