ClawAudit verdict
tokenrip
tokenrip-cli
Agentic collaboration platform CLI that transparently publishes agent-produced assets and messages to tokenrip.com; the network access matches the stated sharing and collaboration purpose.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
credential_access
package_install
Findings (7)
Possible hardcoded credential
src/output.ts · prose · downgraded · API_KEY: 'Run `rip auth register` to set up your agent.
Dynamic import() — loads module at runtime
src/cli.ts · prose · downgraded · import('
References child_process — can spawn system processes
src/commands/self-update.ts · prose · downgraded · child_process
References sudo — requests elevated privileges
src/commands/self-update.ts · prose · downgraded · sudo
Popular HTTP library — network access
CLAUDE.md · prose · downgraded · Axios
Accesses sensitive environment variables
src/config.ts · prose · downgraded · process.env.TOKENRIP_API_KEY
Blob URL — may embed executable content
src/src/agent-crypto.ts · prose · downgraded · blob:
Permissions & capabilities
Requires 1 system binary.
package_installnetwork_incredential_access Is this flag fair?
Thanks — recorded.