← Back to Scanner

cross-device-sync Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

cross-device-sync is an AI agent skill, created by CL Assistant and published at openclaw/skills. ClawSecure audited cross-device-sync across 11 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 98/100 (Safe). The finding concentrates in Verification, including No GitHub source URL - cannot verify agent origin. None were rated high or critical severity.

Is cross-device-sync safe?

ClawSecure audited cross-device-sync and assigned a security score of 98/100 (Safe), identifying 1 finding across Verification. Review the finding below before installing.

What did ClawSecure find in cross-device-sync?

ClawSecure identified 1 finding in cross-device-sync, concentrated in Verification. The most severe is No GitHub source URL - cannot verify agent origin.

How was cross-device-sync audited?

ClawSecure ran cross-device-sync through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 11 files from openclaw/skills.

What does a score of 98 mean?

ClawSecure assigned cross-device-sync a security score of 98/100, placing it in the Safe range. Scores of 80 or above qualify for ClawSecure Verified status; the 1 finding detected is lower-severity. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for cross-device-sync

ClawSecure detected 1 security finding in cross-device-sync, spanning Verification.

Each finding is expandable in the interactive list below.

3-Layer Audit Protocol

Security Recommendations for cross-device-sync

Pin dependencies to exact versions
Unpinned dependencies allow supply-chain attacks where a compromised version is pulled in automatically. Use exact version numbers in package.json (for example 1.2.3 instead of ^1.2.3) to keep unauthorized code out of your dependency tree. ClawSecure checks every dependency against known CVE databases.
Add a config.json permissions manifest
A config.json file declares what permissions an agent component needs: file system access, network requests, shell execution and more. Without it, users have no visibility into what the component can do before installing. Adding a permissions manifest is the single most impactful security improvement for any AI agent skill.

Related Security Research

Best AI Agent Security Tools in 2026: How to ChooseAI Agent Security: The Complete 2026 GuideUnderstanding Our 3-Layer Audit Protocol

Related AI Agent Security Audits

a2aScore 85/100TestFilesScore 95/100deep-research-proScore 85/100gogScore 95/100sql-toolkitScore 95/100

Scanned on February 7, 2026. cross-device-sync is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan