ClawAudit verdict
sendflare-skill
The skill appears to provide a legitimate email sending functionality using the Sendflare API, with clear documentation and no apparent malicious behavior.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Data URI with base64 payload โ may embed malicious content
package/dist/index.js ยท prose ยท downgraded ยท data:application/json;base64,
Long base64 string (100+ chars) โ likely obfuscated payload
package/dist/index.js ยท prose ยท downgraded ยท eyJ2ZXJzaW9uIjozLCJmaWxlIjoiaW5kZXguanMiLCJzb3VyY2VSb290IjoiIiwic291cmNlcyI6WyIu
Permissions & capabilities
No declared permissions โ minimal attack surface.
Is this flag fair?
Thanks โ recorded.