← Back to Scanner

PASB Security Audit Report

πŸ”­ Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

PASB is an AI agent skill, created by AstorYH and published at AstorYH/PASB. ClawSecure audited PASB across 113 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 15/100 (High Risk). The 10 findings concentrate in Malicious Code, Code Injection and ReDoS, including Attempts to access sensitive file: SOUL.md and Attempts to access sensitive file: MEMORY.md. 7 were rated high or critical severity.

Is PASB safe?

ClawSecure audited PASB and assigned a security score of 15/100 (High Risk), identifying 10 findings across Malicious Code and Code Injection. Review the findings below before installing.

What did ClawSecure find in PASB?

ClawSecure identified 10 findings in PASB, concentrated in Malicious Code, Code Injection and ReDoS. 7 were rated high or critical severity. The most severe include Attempts to access sensitive file: SOUL.md and Attempts to access sensitive file: MEMORY.md.

How was PASB audited?

ClawSecure ran PASB through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 113 files from AstorYH/PASB.

What does a score of 15 mean?

ClawSecure assigned PASB a security score of 15/100, placing it in the High Risk range. This is driven by 10 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for PASB

ClawSecure detected 10 security findings in PASB, spanning Malicious Code, Code Injection, ReDoS and Permissions Manifest.

Each finding is expandable in the interactive list below.

3-Layer Audit Protocol

Security Recommendations for PASB

Audit external network connections
PASB connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Eliminate dynamic code execution
PASB evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Fix ReDoS-prone patterns
PASB contains regular expressions vulnerable to catastrophic backtracking (ReDoS). Replace vulnerable patterns, bound input length, and prefer linear-time matching so a crafted input cannot hang the agent.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→

Related AI Agent Security Audits

fzfScore 25/100understand-anythingScore 0/100awesome-openclaw-skillsScore 0/100claude-memScore 15/100gnoScore 5/100

Scanned on April 24, 2026. PASB is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan