← Back to Scanner

clawdefender Security Audit Report

πŸ”­ Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

clawdefender is an AI agent skill, created by nukewire and published at openclaw/skills. ClawSecure audited clawdefender across 4 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 18 findings concentrate in Code Injection, Malicious Code and Unauthorized Tool Use, including Suspicious Pattern: chmod 777 and Suspicious Pattern: /etc/passwd. 14 were rated high or critical severity.

Is clawdefender safe?

ClawSecure audited clawdefender and assigned a security score of 0/100 (High Risk), identifying 18 findings across Code Injection and Malicious Code. Review the findings below before installing.

What did ClawSecure find in clawdefender?

ClawSecure identified 18 findings in clawdefender, concentrated in Code Injection, Malicious Code and Unauthorized Tool Use. 14 were rated high or critical severity. The most severe include Suspicious Pattern: chmod 777 and Suspicious Pattern: /etc/passwd.

How was clawdefender audited?

ClawSecure ran clawdefender through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 4 files from openclaw/skills.

What does a score of 0 mean?

ClawSecure assigned clawdefender a security score of 0/100, placing it in the High Risk range. This is driven by 18 findings led by Code Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for clawdefender

ClawSecure detected 18 security findings in clawdefender, spanning Code Injection, Malicious Code, Unauthorized Tool Use and Prompt Injection.

Showing the 12 highest-severity of 18 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for clawdefender

Eliminate dynamic code execution
clawdefender evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Audit external network connections
clawdefender connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Investigate prompt injection vectors
Prompt injection is one of the most critical threats to AI agents. Attackers can embed malicious instructions in content the agent processes, causing unintended actions. Review every point where clawdefender processes external content and add input validation and output filtering.

Related Security Research

Why Generic Scanners Fail at AI Agent Security→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→

Related AI Agent Security Audits

byterover-cliScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100

Scanned on March 31, 2026. clawdefender is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan