ClawAudit verdict
solana-compression
solana-compression-dev
The skill does not use any capabilities that could be considered risky or dangerous, and it appears to be used legitimately for its stated purpose of creating, updating, closing, burning, and reinitializing compressed accounts on Solana.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
HTTP request to bare IP address โ common in malicious payloads
references/compressed-pdas.md ยท code ยท http://127.0.0.1
Popular HTTP library โ network access
references/error-codes.md ยท prose ยท downgraded ยท got
Permissions & capabilities
Requires 1 environment variable. (1 sensitive: ["API_KEY"] # Helius or Triton RPC key; only needed for devnet/mainnet). Requires 5 system binaries. (1 elevated: cargo).
Is this flag fair?
Thanks โ recorded.