ClawAudit verdict
universal-trading
The skill provides cross-chain token trading using the Particle Network Universal Account SDK, which may pose a risk if not properly validated.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
Opens WebSocket connection
SKILL.md ยท frontmatter ยท WebSocket
Accesses sensitive environment variables
references/examples.md ยท code ยท process.env.PRIVATE_KEY
Popular HTTP library โ network access
scripts/bind-invitation.sh ยท prose ยท downgraded ยท axios
Permissions & capabilities
Requires 2 system binaries. (1 elevated: npm).
Is this flag fair?
Thanks โ recorded.