clawhub is an AI agent skill, created by ClawHub Skill. ClawSecure audited clawhub across 14 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 16 findings concentrate in Malicious Code, Command Injection and Policy Violation, including ClawHavoc C2 infrastructure detected: 91.92.242.30 and ClawHavoc C2 infrastructure detected: 91.92.242.30. 11 were rated high or critical severity.
Is clawhub safe?
ClawSecure audited clawhub and assigned a security score of 0/100 (High Risk), identifying 16 findings across Malicious Code and Command Injection. Review the findings below before installing.
What did ClawSecure find in clawhub?
ClawSecure identified 16 findings in clawhub, concentrated in Malicious Code, Command Injection and Policy Violation. 11 were rated high or critical severity. The most severe include ClawHavoc C2 infrastructure detected: 91.92.242.30 and ClawHavoc C2 infrastructure detected: 91.92.242.30.
How was clawhub audited?
ClawSecure ran clawhub through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 14 files.
What does a score of 0 mean?
ClawSecure assigned clawhub a security score of 0/100, placing it in the High Risk range. This is driven by 16 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for clawhub
ClawSecure detected 16 security findings in clawhub, spanning Malicious Code, Command Injection, Policy Violation and Code Injection.
- critical · ClawHavoc C2 infrastructure detected: 91.92.242.30. Malicious Code finding detected in
SKILL.md. - critical · ClawHavoc C2 infrastructure detected: 91.92.242.30. Malicious Code finding detected in
scan.log. - critical · ClawHavoc C2 infrastructure detected: 91.92.242.30. Malicious Code finding detected in
stdout.json. - critical · ClawHavoc C2 infrastructure detected: 91.92.242.30. Malicious Code finding detected in
verdict.json. - critical · ClawHavoc C2 infrastructure detected: 91.92.242.30. Malicious Code finding detected in
stdout.json. - critical · ClawHavoc C2 infrastructure detected: 91.92.242.30. Malicious Code finding detected in
verdict.json. - high · Pipeline downloads data from the network and executes it:β¦. Command Injection finding detected in
SKILL.md:1. - high · Pipeline downloads data from the network and executes it:β¦. Command Injection finding detected in
scan_logs/cisco/scan.log:1. - high · Pipeline downloads data from the network and executes it:β¦. Command Injection finding detected in
scan_logs/cisco/stdout.json:1. - high · Pipeline downloads data from the network and executes it:β¦. Command Injection finding detected in
scan_logs/cisco/verdict.json:1. - high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
SKILL.md. - medium · Archive scan_logs/clawsecure/skill.zip is corrupt: File isβ¦. Obfuscation finding detected in
scan_logs/clawsecure/skill.zip.
Showing the 12 highest-severity of 16 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for clawhub
Audit external network connections
Harden command execution
Resolve policy violations
Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI AgentsβBeyond Static Scans: Why ClawSecure Verifies Agentic IntentβRelated AI Agent Security Audits
Scanned on March 17, 2026. clawhub is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.