← Back to Scanner

ez-unifi Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

ez-unifi is an AI agent skill, created by araa47 and published at openclaw/skills. ClawSecure audited ez-unifi across 3 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 20/100 (High Risk). The 17 findings concentrate in Transitive Trust Abuse, Data Exfiltration and Policy Violation, including Pattern detected: import aiohttp and Skill code uses network libraries but doesn't declare network.... None were rated high or critical severity.

Is ez-unifi safe?

ClawSecure audited ez-unifi and assigned a security score of 20/100 (High Risk), identifying 17 findings across Transitive Trust Abuse and Data Exfiltration. Review the findings below before installing.

What did ClawSecure find in ez-unifi?

ClawSecure identified 17 findings in ez-unifi, concentrated in Transitive Trust Abuse, Data Exfiltration and Policy Violation. The most severe include Pattern detected: import aiohttp and Skill code uses network libraries but doesn't declare network....

How was ez-unifi audited?

ClawSecure ran ez-unifi through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 3 files from openclaw/skills.

What does a score of 20 mean?

ClawSecure assigned ez-unifi a security score of 20/100, placing it in the High Risk range. This is driven by 17 findings led by Transitive Trust Abuse that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for ez-unifi

ClawSecure detected 17 security findings in ez-unifi, spanning Transitive Trust Abuse, Data Exfiltration, Policy Violation and Unauthorized Tool Use.

Showing the 12 highest-severity of 17 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for ez-unifi

Audit external network connections
ez-unifi sends data to external endpoints. Confirm each destination is expected and authorized, and remove any callback that exfiltrates data. ClawSecure monitors for known exfiltration and C2 endpoints.
Resolve policy violations
ez-unifi trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.
Add a config.json permissions manifest
A config.json file declares what an agent component can access: file system, network, shell execution and more. Without it, users have no visibility into what the component can do before installing. This is the single most impactful security improvement for any AI agent skill.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI AgentsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

open-webuiScore 35/100fzfScore 25/100claude-memScore 35/1009c0a7c48db776b22Score 25/1009c0a7c48db776b22Score 25/100

Scanned on February 7, 2026. ez-unifi is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan