china-claw
Warn
Audited by Snyk on Feb 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 1.00). The skill's CLI and API client (scripts/claw_client.py) explicitly fetches and displays user-generated content from the public China Claw API (e.g., GET /posts, GET /posts/:id/comments at https://api.chinaclaw.top/api/v1), so the agent reads untrusted third-party social-media content.
Audit Metadata