← Back to Scanner

glance Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

glance is an AI agent skill, created by acfranzen and published at acfranzen/glance. ClawSecure audited glance across 109 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 67 findings concentrate in Data Exfiltration, Code Injection and Supply Chain, including Pattern detected: ghp_**** and Pattern detected: new Function(. 15 were rated high or critical severity.

Is glance safe?

ClawSecure audited glance and assigned a security score of 0/100 (High Risk), identifying 67 findings across Data Exfiltration and Code Injection. Review the findings below before installing.

What did ClawSecure find in glance?

ClawSecure identified 67 findings in glance, concentrated in Data Exfiltration, Code Injection and Supply Chain. 15 were rated high or critical severity. The most severe include Pattern detected: ghp_**** and Pattern detected: new Function(.

How was glance audited?

ClawSecure ran glance through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 109 files from acfranzen/glance.

What does a score of 0 mean?

ClawSecure assigned glance a security score of 0/100, placing it in the High Risk range. This is driven by 67 findings led by Data Exfiltration that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for glance

ClawSecure detected 67 security findings in glance, spanning Data Exfiltration, Code Injection, Supply Chain and Policy Violation.

Showing the 12 highest-severity of 67 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for glance

Audit external network connections
glance sends data to external endpoints. Confirm each destination is expected and authorized, and remove any callback that exfiltrates data. ClawSecure monitors for known exfiltration and C2 endpoints.
Eliminate dynamic code execution
glance evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Update and pin dependencies
glance depends on packages with supply-chain risk. Pin every dependency to an exact version, update packages with known CVEs to patched releases, and re-audit after each change. ClawSecure checks every dependency against known CVE databases.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI AgentsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

awesome-openclaw-skillsScore 0/100memUScore 0/100understand-anythingScore 0/10062ac696296b54aadScore 0/1006bc837afc1a86e89Score 0/100

Scanned on May 2, 2026. glance is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan