← Back to Scanner

clawhub Security Audit Report

πŸ”­ Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

clawhub is an AI agent skill, created by ClawHub Skill. ClawSecure audited clawhub across 14 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 16 findings concentrate in Malicious Code, Command Injection and Policy Violation, including ClawHavoc C2 infrastructure detected: 91.92.242.30 and ClawHavoc C2 infrastructure detected: 91.92.242.30. 11 were rated high or critical severity.

Is clawhub safe?

ClawSecure audited clawhub and assigned a security score of 0/100 (High Risk), identifying 16 findings across Malicious Code and Command Injection. Review the findings below before installing.

What did ClawSecure find in clawhub?

ClawSecure identified 16 findings in clawhub, concentrated in Malicious Code, Command Injection and Policy Violation. 11 were rated high or critical severity. The most severe include ClawHavoc C2 infrastructure detected: 91.92.242.30 and ClawHavoc C2 infrastructure detected: 91.92.242.30.

How was clawhub audited?

ClawSecure ran clawhub through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 14 files.

What does a score of 0 mean?

ClawSecure assigned clawhub a security score of 0/100, placing it in the High Risk range. This is driven by 16 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for clawhub

ClawSecure detected 16 security findings in clawhub, spanning Malicious Code, Command Injection, Policy Violation and Code Injection.

Showing the 12 highest-severity of 16 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for clawhub

Audit external network connections
clawhub connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Harden command execution
clawhub constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Resolve policy violations
clawhub trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→

Related AI Agent Security Audits

AI-Agent-Risk-EvaluationScore 0/100self-improvementScore 0/100GUI Agent HarnessScore 0/100braindbScore 0/100System Health Monitor ProScore 0/100

Scanned on March 17, 2026. clawhub is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan