← Back to Scanner

byterover-cli Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

byterover-cli is an AI agent skill, created by ByteRover and published at campfirein/byterover-cli. ClawSecure audited byterover-cli across 106 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 18 findings concentrate in Code Injection, Supply Chain and Permissions Manifest, including Potentially dangerous code pattern detected: curl.*\|.*sh and Potentially dangerous code pattern detected: curl.*\|.*sh. 13 were rated high or critical severity.

Is byterover-cli safe?

ClawSecure audited byterover-cli and assigned a security score of 0/100 (High Risk), identifying 18 findings across Code Injection and Supply Chain. Review the findings below before installing.

What did ClawSecure find in byterover-cli?

ClawSecure identified 18 findings in byterover-cli, concentrated in Code Injection, Supply Chain and Permissions Manifest. 13 were rated high or critical severity. The most severe include Potentially dangerous code pattern detected: curl.*\|.*sh and Potentially dangerous code pattern detected: curl.*\|.*sh.

How was byterover-cli audited?

ClawSecure ran byterover-cli through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 106 files from campfirein/byterover-cli.

What does a score of 0 mean?

ClawSecure assigned byterover-cli a security score of 0/100, placing it in the High Risk range. This is driven by 18 findings led by Code Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for byterover-cli

ClawSecure detected 18 security findings in byterover-cli, spanning Code Injection, Supply Chain and Permissions Manifest.

Showing the 12 highest-severity of 18 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for byterover-cli

Eliminate dynamic code execution
byterover-cli evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Update and pin dependencies
byterover-cli depends on packages with supply-chain risk. Pin every dependency to an exact version, update packages with known CVEs to patched releases, and re-audit after each change. ClawSecure checks every dependency against known CVE databases.
Add a config.json permissions manifest
A config.json file declares what an agent component can access: file system, network, shell execution and more. Without it, users have no visibility into what the component can do before installing. This is the single most impactful security improvement for any AI agent skill.

Related Security Research

Why Generic Scanners Fail at AI Agent SecurityBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

79129ab11fed32e9Score 0/100a4b01e81f20e9814Score 0/1006bc837afc1a86e89Score 0/10062ac696296b54aadScore 0/10080e3abb00251d455Score 0/100

Scanned on June 25, 2026. byterover-cli is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan