ClawAudit verdict
tushare-future-data
The skill provides a clear and transparent interface for fetching Tushare Pro futures data, with a specified set of 14 core interfaces and well-documented parameters.
β Flagged for review β coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis β not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Possible hardcoded credential
README.md Β· prose Β· downgraded Β· TOKEN="δ½ ηtokenε符串
Python os.environ.get β reads environment variable
__init__.py Β· prose Β· downgraded Β· os.environ.get(
Permissions & capabilities
No declared permissions β minimal attack surface.
Is this flag fair?
Thanks β recorded.