clawhub is an AI agent skill, created by ClawHub Skill. ClawSecure audited clawhub across 14 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 15 findings concentrate in Command Injection, Obfuscation and Policy Violation, including Pipeline downloads data from the network and executes it:β¦ and Pipeline downloads data from the network and executes it:β¦. 9 were rated high or critical severity.
Is clawhub safe?
ClawSecure audited clawhub and assigned a security score of 0/100 (High Risk), identifying 15 findings across Command Injection and Obfuscation. Review the findings below before installing.
What did ClawSecure find in clawhub?
ClawSecure identified 15 findings in clawhub, concentrated in Command Injection, Obfuscation and Policy Violation. 9 were rated high or critical severity. The most severe include Pipeline downloads data from the network and executes it:β¦ and Pipeline downloads data from the network and executes it:β¦.
How was clawhub audited?
ClawSecure ran clawhub through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 14 files.
What does a score of 0 mean?
ClawSecure assigned clawhub a security score of 0/100, placing it in the High Risk range. This is driven by 15 findings led by Command Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for clawhub
ClawSecure detected 15 security findings in clawhub, spanning Command Injection, Obfuscation, Policy Violation and Code Injection.
- high · Pipeline downloads data from the network and executes it:β¦. Command Injection finding detected in
scan_logs/cisco/scan.log:1. - high · Pipeline downloads data from the network and executes it:β¦. Command Injection finding detected in
scan_logs/cisco/scan.log:1. - high · Pipeline uses obfuscation before code execution: `base64 -dβ¦. Obfuscation finding detected in
scan_logs/cisco/scan.log:1. - high · Pipeline downloads data from the network and executes it:β¦. Command Injection finding detected in
scan_logs/cisco/stdout.json:1. - high · Pipeline downloads data from the network and executes it:β¦. Command Injection finding detected in
scan_logs/cisco/stdout.json:1. - high · Pipeline uses obfuscation before code execution: `base64 -dβ¦. Obfuscation finding detected in
scan_logs/cisco/stdout.json:1. - high · Pipeline downloads data from the network and executes it:β¦. Command Injection finding detected in
scan_logs/cisco/verdict.json:1. - high · Pipeline uses obfuscation before code execution: `base64 -dβ¦. Obfuscation finding detected in
scan_logs/cisco/verdict.json:1. - high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
SKILL.md. - medium · Archive scan_logs/clawsecure/skill.zip is corrupt: File isβ¦. Obfuscation finding detected in
scan_logs/clawsecure/skill.zip. - medium · Archive file found: scan_logs/clawsecure/skill.zip.β¦. Policy Violation finding detected in
scan_logs/clawsecure/skill.zip. - medium · Binary file 'scan_logs/clawsecure/skill.zip' cannot beβ¦. Policy Violation finding detected in
scan_logs/clawsecure/skill.zip.
Showing the 12 highest-severity of 15 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for clawhub
Harden command execution
Review obfuscated or hidden code
Resolve policy violations
Related Security Research
Why Generic Scanners Fail at AI Agent SecurityβUnderstanding Our 3-Layer Audit ProtocolβRelated AI Agent Security Audits
Scanned on March 17, 2026. clawhub is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.