ClawAudit verdict
unified-dev-monitor
sol-bsc-dev-monitor
The skill uses package installation, but it appears to be used legitimately for its stated purpose of monitoring developer wallets on BSC and Solana.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (2)
Possible hardcoded credential
billing-final.js ยท prose ยท downgraded ยท API_KEY = 'sk_f072a786149bc07fc8730b4683dc00f3e050e72441922284ca803cdee2b994b5
Popular HTTP library โ network access
SKILL.md ยท prose ยท downgraded ยท axios
Permissions & capabilities
No declared permissions โ minimal attack surface.
package_install Is this flag fair?
Thanks โ recorded.