ClawAudit verdict
trading-card-specialist2
trading-card-specialist
Trading card analysis and eBay listing optimization skill that operates in no-credential mode by default and only uses optional eBay/PSA credentials when explicitly configured; no exfiltration or deceptive behavior.
β Flagged for review β coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis β not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (1)
Possible hardcoded credential
CREDENTIALS.md Β· code Β· TOKEN="your_production_user_token
Permissions & capabilities
No declared permissions β minimal attack surface.
Is this flag fair?
Thanks β recorded.