← Back to Scanner

clawhub Security Audit Report

πŸ”­ Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

clawhub is an AI agent skill, created by ClawHub Skill. ClawSecure audited clawhub across 14 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 15 findings concentrate in Command Injection, Obfuscation and Policy Violation, including Pipeline downloads data from the network and executes it:… and Pipeline downloads data from the network and executes it:…. 9 were rated high or critical severity.

Is clawhub safe?

ClawSecure audited clawhub and assigned a security score of 0/100 (High Risk), identifying 15 findings across Command Injection and Obfuscation. Review the findings below before installing.

What did ClawSecure find in clawhub?

ClawSecure identified 15 findings in clawhub, concentrated in Command Injection, Obfuscation and Policy Violation. 9 were rated high or critical severity. The most severe include Pipeline downloads data from the network and executes it:… and Pipeline downloads data from the network and executes it:….

How was clawhub audited?

ClawSecure ran clawhub through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 14 files.

What does a score of 0 mean?

ClawSecure assigned clawhub a security score of 0/100, placing it in the High Risk range. This is driven by 15 findings led by Command Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for clawhub

ClawSecure detected 15 security findings in clawhub, spanning Command Injection, Obfuscation, Policy Violation and Code Injection.

Showing the 12 highest-severity of 15 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for clawhub

Harden command execution
clawhub constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Review obfuscated or hidden code
clawhub contains obfuscated or hidden content that resists review. Inspect encoded, minified or hidden files to confirm they are not concealing unexpected behavior before installing.
Resolve policy violations
clawhub trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.

Related Security Research

Why Generic Scanners Fail at AI Agent Security→Understanding Our 3-Layer Audit Protocol→

Related AI Agent Security Audits

byterover-cliScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100

Scanned on March 17, 2026. clawhub is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan