whatsmolt is an AI agent skill, created by Goudan and published at crypticdriver/whatsmolt. ClawSecure audited whatsmolt across 50 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 11/100 (High Risk). The 17 findings concentrate in Supply Chain and Permissions Manifest, including Vulnerability in next@15.1.3: Next.js is vulnerable to RCE in React... and Vulnerability in next@15.1.3: Authorization Bypass in Next.js Middleware. 6 were rated high or critical severity.
Is whatsmolt safe?
ClawSecure audited whatsmolt and assigned a security score of 11/100 (High Risk), identifying 17 findings across Supply Chain and Permissions Manifest. Review the findings below before installing.
What did ClawSecure find in whatsmolt?
ClawSecure identified 17 findings in whatsmolt, concentrated in Supply Chain and Permissions Manifest. 6 were rated high or critical severity. The most severe include Vulnerability in next@15.1.3: Next.js is vulnerable to RCE in React... and Vulnerability in next@15.1.3: Authorization Bypass in Next.js Middleware.
How was whatsmolt audited?
ClawSecure ran whatsmolt through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 50 files from crypticdriver/whatsmolt.
What does a score of 11 mean?
ClawSecure assigned whatsmolt a security score of 11/100, placing it in the High Risk range. This is driven by 17 findings led by Supply Chain that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for whatsmolt
ClawSecure detected 17 security findings in whatsmolt, spanning Supply Chain and Permissions Manifest.
- critical · Vulnerability in next@15.1.3: Next.js is vulnerable to RCE in React.... Supply Chain finding detected in
package.json. - critical · Vulnerability in next@15.1.3: Authorization Bypass in Next.js Middleware. Supply Chain finding detected in
package.json. - high · Vulnerability in next@15.1.3: Next.JS vulnerability can lead to DoS via.... Supply Chain finding detected in
package.json. - high · Vulnerability in next@15.1.3: Next.js HTTP request deserialization can.... Supply Chain finding detected in
package.json. - high · Vulnerability in next@15.1.3: Next Vulnerable to Denial of Service with.... Supply Chain finding detected in
package.json. - high · Vulnerability in next@15.1.3: Next.js has a Denial of Service with.... Supply Chain finding detected in
package.json. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- low · Vulnerability in next@15.1.3: Information exposure in Next.js dev.... Supply Chain finding detected in
package.json. - low · Vulnerability in next@15.1.3: Next.js Race Condition to Cache Poisoning. Supply Chain finding detected in
package.json. - moderate · Vulnerability in next@15.1.3: Next.js: Unbounded next/image disk cache.... Supply Chain finding detected in
package.json. - moderate · Vulnerability in next@15.1.3: Next.js Improper Middleware Redirect.... Supply Chain finding detected in
package.json. - moderate · Vulnerability in next@15.1.3: Next.js self-hosted applications.... Supply Chain finding detected in
package.json.
Showing the 12 highest-severity of 17 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for whatsmolt
Update and pin dependencies
Add a config.json permissions manifest
Pin dependencies to exact versions
1.2.3 instead of ^1.2.3) to keep unauthorized code out of your dependency tree. ClawSecure checks every dependency against known CVE databases.Related Security Research
AI Agent Supply Chain Attacks: How Dependencies Become Weapons→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on May 2, 2026. whatsmolt is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.