← Back to Scanner

nginx-analyze Security Audit Report

πŸ”­ Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

nginx-analyze is an AI agent skill. ClawSecure audited nginx-analyze across 8 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 60/100 (Medium Risk). The 6 findings concentrate in Code Injection, Command Injection and Obfuscation, including OS Command Execution and Potentially dangerous code pattern detected: system\(. 3 were rated high or critical severity.

Is nginx-analyze safe?

ClawSecure audited nginx-analyze and assigned a security score of 60/100 (Medium Risk), identifying 6 findings across Code Injection and Command Injection. Review the findings below before installing.

What did ClawSecure find in nginx-analyze?

ClawSecure identified 6 findings in nginx-analyze, concentrated in Code Injection, Command Injection and Obfuscation. 3 were rated high or critical severity. The most severe include OS Command Execution and Potentially dangerous code pattern detected: system\(.

How was nginx-analyze audited?

ClawSecure ran nginx-analyze through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 8 files.

What does a score of 60 mean?

ClawSecure assigned nginx-analyze a security score of 60/100, placing it in the Medium Risk range. This reflects 6 findings led by Code Injection that warrant review before production use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for nginx-analyze

ClawSecure detected 6 security findings in nginx-analyze, spanning Code Injection, Command Injection, Obfuscation and Permissions Manifest.

Each finding is expandable in the interactive list below.

3-Layer Audit Protocol

Security Recommendations for nginx-analyze

Eliminate dynamic code execution
nginx-analyze evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Harden command execution
nginx-analyze constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Review obfuscated or hidden code
nginx-analyze contains obfuscated or hidden content that resists review. Inspect encoded, minified or hidden files to confirm they are not concealing unexpected behavior before installing.

Related Security Research

Why Generic Scanners Fail at AI Agent Security→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→

Related AI Agent Security Audits

gitlab-cli-skillsScore 55/100devops-mainScore 75/100devops-mainScore 75/100devops-mainScore 75/100skill-vetter-v2Score 70/100

Scanned on June 12, 2026. nginx-analyze is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan