ClawAudit verdict
signup-lead
The skill sends lead details to an external API endpoint for creating signup leads. The use of an API key for authentication and the explicit mention of configuration requirements suggest a standard and secure approach.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (1)
Possible hardcoded credential
SKILL.yaml ยท prose ยท downgraded ยท API_KEY="your-real-key-here
Permissions & capabilities
No declared permissions โ minimal attack surface.
Is this flag fair?
Thanks โ recorded.