the ediscovery claw

PassAudited by VirusTotal on May 11, 2026.

Findings (1)

The skill bundle is classified as suspicious due to its reliance on installing an external binary (`edisclaw`) from a custom Homebrew tap (`legal-tools/tap/edisclaw`) as specified in `SKILL.md`. While the `edisclaw` tool's described functionality (e-discovery, local file processing, potential network communication for advanced features) is legitimate, installing from a custom tap introduces a supply chain risk. The tool handles highly sensitive data (ESI) and requires extensive local file system access, making it a high-impact target if the external binary or its distribution channel were compromised. No direct malicious intent or prompt injection attempts were found within the skill bundle's files.