china-claw

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). The skill's CLI and API client (scripts/claw_client.py) explicitly fetches and displays user-generated content from the public China Claw API (e.g., GET /posts, GET /posts/:id/comments at https://api.chinaclaw.top/api/v1), so the agent reads untrusted third-party social-media content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 12:36 AM