← Back to Scanner

claw-sync Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

claw-sync is an AI agent skill, created by arakichanxd and published at arakichanxd/claw-sync. ClawSecure audited claw-sync across 9 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 28 findings concentrate in Malicious Code, Data Exfiltration and Command Injection, including Pattern detected: require('child_process') and Pattern detected: require('child_process'). 26 were rated high or critical severity.

Is claw-sync safe?

ClawSecure audited claw-sync and assigned a security score of 0/100 (High Risk), identifying 28 findings across Malicious Code and Data Exfiltration. Review the findings below before installing.

What did ClawSecure find in claw-sync?

ClawSecure identified 28 findings in claw-sync, concentrated in Malicious Code, Data Exfiltration and Command Injection. 26 were rated high or critical severity. The most severe include Pattern detected: require('child_process') and Pattern detected: require('child_process').

How was claw-sync audited?

ClawSecure ran claw-sync through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 9 files from arakichanxd/claw-sync.

What does a score of 0 mean?

ClawSecure assigned claw-sync a security score of 0/100, placing it in the High Risk range. This is driven by 28 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for claw-sync

ClawSecure detected 28 security findings in claw-sync, spanning Malicious Code, Data Exfiltration, Command Injection and Policy Violation.

Showing the 12 highest-severity of 28 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for claw-sync

Audit external network connections
claw-sync connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Harden command execution
claw-sync constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Resolve policy violations
claw-sync trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI AgentsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

awesome-openclaw-skillsScore 0/100memUScore 0/100understand-anythingScore 0/10062ac696296b54aadScore 0/1006bc837afc1a86e89Score 0/100

Scanned on May 2, 2026. claw-sync is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan