ClawAudit verdict
rss-reader
rss-reader-skill
RSS aggregator with AI summarization that uses user-configured OpenAI/Zhipu API key and optional Feishu webhook; all data flows go to user-chosen destinations with no unexpected exfiltration.
β Flagged for review β coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis β not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
credential_access
package_install
Findings (4)
Possible hardcoded credential
SKILL.md Β· code Β· API_KEY="δ½ ηζΊθ°±API Key
References webhook/callback URL
SKILL.md Β· code Β· WEBHOOK_URL
pip3 install β installs Python packages at runtime
SKILL.md Β· code Β· pip3 install
Python os.getenv β reads environment variable
rss_reader.py Β· prose Β· downgraded Β· os.getenv(
Permissions & capabilities
No declared permissions β minimal attack surface.
credential_accessnetwork_inpackage_install Is this flag fair?
Thanks β recorded.