confidant is an AI agent skill, created by ericsantos and published at openclaw/skills. ClawSecure audited confidant across 2 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 95/100 (Safe). The 3 findings concentrate in Policy Violation and Permissions Manifest, including Missing config.json - agent may not be properly configured and Skill name 'Confidant' is invalid. Agent skills require lowercase.... None were rated high or critical severity.
Is confidant safe?
ClawSecure audited confidant and assigned a security score of 95/100 (Safe), identifying 3 findings across Policy Violation and Permissions Manifest. Review the findings below before installing.
What did ClawSecure find in confidant?
ClawSecure identified 3 findings in confidant, concentrated in Policy Violation and Permissions Manifest. The most severe include Missing config.json - agent may not be properly configured and Skill name 'Confidant' is invalid. Agent skills require lowercase....
How was confidant audited?
ClawSecure ran confidant through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 2 files from openclaw/skills.
What does a score of 95 mean?
ClawSecure assigned confidant a security score of 95/100, placing it in the Safe range. Scores of 80 or above qualify for ClawSecure Verified status; the 3 findings detected are lower-severity. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for confidant
ClawSecure detected 3 security findings in confidant, spanning Policy Violation and Permissions Manifest.
- medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- info · Skill name 'Confidant' is invalid. Agent skills require lowercase.... Policy Violation finding detected in
SKILL.md. - info · Skill manifest does not include a 'license' field. Specifying a license.... Policy Violation finding detected in
SKILL.md.
Each finding is expandable in the interactive list below.
3-Layer Audit Protocol
Security Recommendations for confidant
Resolve policy violations
Add a config.json permissions manifest
Pin dependencies to exact versions
1.2.3 instead of ^1.2.3) to keep unauthorized code out of your dependency tree. ClawSecure checks every dependency against known CVE databases.Related Security Research
OWASP ASI Top 10 Explained: The Complete Guide to AI Agent Security Standards→Understanding Our 3-Layer Audit Protocol→How to Secure an MCP Server: The 2026 Guide→Related AI Agent Security Audits
Scanned on February 7, 2026. confidant is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.