ClawAudit verdict
vacation-rental-management
Variant of the TIDY vacation property management skill with expanded metadata; same safe API client pattern with TIDY_API_TOKEN and public-api.tidy.com as the sole destination.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
network_out
package_install
Findings (2)
Possible hardcoded credential
references/authentication.md ยท code ยท TOKEN="abc123...
Popular HTTP library โ network access
references/vacation-workflows.md ยท code ยท got
Permissions & capabilities
Requires 1 environment variable. (1 sensitive: TIDY_API_TOKEN).
package_installnetwork_innetwork_out Is this flag fair?
Thanks โ recorded.