← Back to Scanner

openclaw-bastion-pro Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

openclaw-bastion-pro is an AI agent skill, created by atlaspa and published at openclaw/skills. ClawSecure audited openclaw-bastion-pro across 4 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 21 findings concentrate in Prompt Injection, Command Injection and Code Injection, including Pattern detected: :(){ :|:& };: and Detects prompt strings used to override or force malicious tool calls:.... 19 were rated high or critical severity.

Is openclaw-bastion-pro safe?

ClawSecure audited openclaw-bastion-pro and assigned a security score of 0/100 (High Risk), identifying 21 findings across Prompt Injection and Command Injection. Review the findings below before installing.

What did ClawSecure find in openclaw-bastion-pro?

ClawSecure identified 21 findings in openclaw-bastion-pro, concentrated in Prompt Injection, Command Injection and Code Injection. 19 were rated high or critical severity. The most severe include Pattern detected: :(){ :|:& };: and Detects prompt strings used to override or force malicious tool calls:....

How was openclaw-bastion-pro audited?

ClawSecure ran openclaw-bastion-pro through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 4 files from openclaw/skills.

What does a score of 0 mean?

ClawSecure assigned openclaw-bastion-pro a security score of 0/100, placing it in the High Risk range. This is driven by 21 findings led by Prompt Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for openclaw-bastion-pro

ClawSecure detected 21 security findings in openclaw-bastion-pro, spanning Prompt Injection, Command Injection, Code Injection and Malicious Code.

Showing the 12 highest-severity of 21 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for openclaw-bastion-pro

Investigate prompt injection vectors
Prompt injection is one of the most critical threats to AI agents. Attackers can embed malicious instructions in content the agent processes, causing unintended actions. Review every point where openclaw-bastion-pro processes external content and add input validation and output filtering.
Harden command execution
openclaw-bastion-pro constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Eliminate dynamic code execution
openclaw-bastion-pro evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.

Related Security Research

The Sleeper Agent Problem: Why a Clean Scan Today Does Not Guarantee Safety TomorrowOWASP ASI Top 10 Explained: The Complete Guide to AI Agent Security Standards

Related AI Agent Security Audits

byterover-cliScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100

Scanned on February 7, 2026. openclaw-bastion-pro is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan