clawdefender Security Audit Report
clawdefender is an AI agent skill, created by nukewire and published at openclaw/skills. ClawSecure audited clawdefender across 4 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 18 findings concentrate in Code Injection, Malicious Code and Unauthorized Tool Use, including Suspicious Pattern: chmod 777 and Suspicious Pattern: /etc/passwd. 14 were rated high or critical severity.
Is clawdefender safe?
ClawSecure audited clawdefender and assigned a security score of 0/100 (High Risk), identifying 18 findings across Code Injection and Malicious Code. Review the findings below before installing.
What did ClawSecure find in clawdefender?
ClawSecure identified 18 findings in clawdefender, concentrated in Code Injection, Malicious Code and Unauthorized Tool Use. 14 were rated high or critical severity. The most severe include Suspicious Pattern: chmod 777 and Suspicious Pattern: /etc/passwd.
How was clawdefender audited?
ClawSecure ran clawdefender through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 4 files from openclaw/skills.
What does a score of 0 mean?
ClawSecure assigned clawdefender a security score of 0/100, placing it in the High Risk range. This is driven by 18 findings led by Code Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for clawdefender
ClawSecure detected 18 security findings in clawdefender, spanning Code Injection, Malicious Code, Unauthorized Tool Use and Prompt Injection.
- critical · Suspicious Pattern: chmod 777. Unauthorized Tool Use finding detected in
scripts/clawdefender.sh:147. - critical · Suspicious Pattern: /etc/passwd. Unauthorized Tool Use finding detected in
scripts/clawdefender.sh:214. - critical · Suspicious Pattern: /etc/shadow. Unauthorized Tool Use finding detected in
scripts/clawdefender.sh:215. - critical · Suspicious domain detected: webhook.site (potential dataβ¦. Malicious Code finding detected in
SKILL.md. - critical · Suspicious domain detected: webhook.site (potential dataβ¦. Malicious Code finding detected in
clawdefender.sh. - high · Suspicious Pattern: ignore previous instructions. Prompt Injection finding detected in
SKILL.md:98. - high · Suspicious Pattern: ignore previous instructions. Prompt Injection finding detected in
SKILL.md:129. - high · Attempts to access sensitive file: .ssh/. Malicious Code finding detected in
SKILL.md. - high · Attempts to access sensitive file: .ssh/. Malicious Code finding detected in
clawdefender.sh. - high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
SKILL.md. - high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
clawdefender.sh. - high · Potentially dangerous code pattern detected: wget.*\|.*sh. Code Injection finding detected in
clawdefender.sh.
Showing the 12 highest-severity of 18 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for clawdefender
Eliminate dynamic code execution
Audit external network connections
Investigate prompt injection vectors
Related Security Research
Why Generic Scanners Fail at AI Agent SecurityβBeyond Static Scans: Why ClawSecure Verifies Agentic IntentβRelated AI Agent Security Audits
Scanned on March 31, 2026. clawdefender is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.