ClawAudit verdict
windsurf-cascade
Receives external input AND uses eval
Reference documentation skill for the Windsurf IDE and Cascade AI agent; dynamic_eval is referenced in the context of IDE features, not remote code execution, and content is a benign how-to guide.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
What it does
These are capability combinations: each listed behavior occurs in the skill, but ClawAudit detects co-occurrence — it does not verify that one flows into another. Read the code to confirm a live chain.
Receives external input AND uses eval — the remote code-injection pattern (data-flow not verified)
LLM01 · LLM05 · ASI01 · ASI05
Findings (2)
References sudo — requests elevated privileges
SKILL.md · code · sudo
References agent configuration files
SKILL.md · prose · downgraded · CLAUDE.md
Permissions & capabilities
No declared permissions — minimal attack surface.
dynamic_evalnetwork_in Thanks — recorded.