glance is an AI agent skill, created by acfranzen and published at acfranzen/glance. ClawSecure audited glance across 109 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 67 findings concentrate in Data Exfiltration, Code Injection and Supply Chain, including Pattern detected: ghp_**** and Pattern detected: new Function(. 15 were rated high or critical severity.
Is glance safe?
ClawSecure audited glance and assigned a security score of 0/100 (High Risk), identifying 67 findings across Data Exfiltration and Code Injection. Review the findings below before installing.
What did ClawSecure find in glance?
ClawSecure identified 67 findings in glance, concentrated in Data Exfiltration, Code Injection and Supply Chain. 15 were rated high or critical severity. The most severe include Pattern detected: ghp_**** and Pattern detected: new Function(.
How was glance audited?
ClawSecure ran glance through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 109 files from acfranzen/glance.
What does a score of 0 mean?
ClawSecure assigned glance a security score of 0/100, placing it in the High Risk range. This is driven by 67 findings led by Data Exfiltration that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for glance
ClawSecure detected 67 security findings in glance, spanning Data Exfiltration, Code Injection, Supply Chain and Policy Violation.
- critical · Pattern detected: ghp_****. Hardcoded Secrets finding detected in
docs/widget-sdk.md:585. - critical · Pattern detected: new Function(. Command Injection finding detected in
src/lib/widget-sdk/context.ts:144. - high · Only 39% of skill content could be analyzed. 66 of 109 files are opaque.... Policy Violation finding.
- high · Pattern detected: fs.readFileSync(. Data Exfiltration finding detected in
src/lib/credentials.ts:156. - high · Pattern detected: fs.writeFileSync(. Data Exfiltration finding detected in
src/lib/credentials.ts:173. - high · Pattern detected: fs.readFileSync(. Data Exfiltration finding detected in
src/lib/widget-sdk/server-executor.ts:124. - high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
README.md. - high · Potentially dangerous code pattern detected: exec\(. Code Injection finding detected in
SKILL.md. - high · Potentially dangerous code pattern detected: eval\(. Code Injection finding detected in
widget-sdk.md. - high · Potentially dangerous code pattern detected: exec\(. Code Injection finding detected in
widget-sdk.md. - high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
install.sh. - high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
install.sh.
Showing the 12 highest-severity of 67 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for glance
Audit external network connections
Eliminate dynamic code execution
Update and pin dependencies
Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on May 2, 2026. glance is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.