← Back to Scanner

deepclaw Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

deepclaw is an AI agent skill, created by antibitcoin and published at antibitcoin/deepclaw. ClawSecure audited deepclaw across 15 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 73/100 (Medium Risk). The 6 findings concentrate in Supply Chain, Permissions Manifest and Code Injection, including Potentially dangerous code pattern detected: exec\( and Vulnerability in fastify@4.25.0: Fastify's Content-Type header tab.... 2 were rated high or critical severity.

Is deepclaw safe?

ClawSecure audited deepclaw and assigned a security score of 73/100 (Medium Risk), identifying 6 findings across Supply Chain and Permissions Manifest. Review the findings below before installing.

What did ClawSecure find in deepclaw?

ClawSecure identified 6 findings in deepclaw, concentrated in Supply Chain, Permissions Manifest and Code Injection. 2 were rated high or critical severity. The most severe include Potentially dangerous code pattern detected: exec\( and Vulnerability in fastify@4.25.0: Fastify's Content-Type header tab....

How was deepclaw audited?

ClawSecure ran deepclaw through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 15 files from antibitcoin/deepclaw.

What does a score of 73 mean?

ClawSecure assigned deepclaw a security score of 73/100, placing it in the Medium Risk range. This reflects 6 findings led by Supply Chain that warrant review before production use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for deepclaw

ClawSecure detected 6 security findings in deepclaw, spanning Supply Chain, Permissions Manifest and Code Injection.

Each finding is expandable in the interactive list below.

3-Layer Audit Protocol

Security Recommendations for deepclaw

Update and pin dependencies
deepclaw depends on packages with supply-chain risk. Pin every dependency to an exact version, update packages with known CVEs to patched releases, and re-audit after each change. ClawSecure checks every dependency against known CVE databases.
Add a config.json permissions manifest
A config.json file declares what an agent component can access: file system, network, shell execution and more. Without it, users have no visibility into what the component can do before installing. This is the single most impactful security improvement for any AI agent skill.
Eliminate dynamic code execution
deepclaw evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.

Related Security Research

AI Agent Supply Chain Attacks: How Dependencies Become WeaponsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

zeroclawScore 85/100GitNexusScore 75/100Anthropic-Cybersecurity-SkillsScore 70/100antigravity-awesome-skillsScore 75/100aitorScore 61/100

Scanned on May 5, 2026. deepclaw is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan