← Back to Scanner

wordpress-publisher Security Audit Report

πŸ”­ Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

wordpress-publisher is an AI agent skill, created by ClawHub Skill. ClawSecure audited wordpress-publisher across 20 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 30/100 (High Risk). The 14 findings concentrate in Data Exfiltration, ReDoS and Code Injection, including Potentially dangerous code pattern detected: base64.*decode and Undeclared Network Access. 1 was rated high or critical severity.

Is wordpress-publisher safe?

ClawSecure audited wordpress-publisher and assigned a security score of 30/100 (High Risk), identifying 14 findings across Data Exfiltration and ReDoS. Review the findings below before installing.

What did ClawSecure find in wordpress-publisher?

ClawSecure identified 14 findings in wordpress-publisher, concentrated in Data Exfiltration, ReDoS and Code Injection. 1 was rated high or critical severity. The most severe include Potentially dangerous code pattern detected: base64.*decode and Undeclared Network Access.

How was wordpress-publisher audited?

ClawSecure ran wordpress-publisher through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 20 files.

What does a score of 30 mean?

ClawSecure assigned wordpress-publisher a security score of 30/100, placing it in the High Risk range. This is driven by 14 findings led by Data Exfiltration that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for wordpress-publisher

ClawSecure detected 14 security findings in wordpress-publisher, spanning Data Exfiltration, ReDoS, Code Injection and Unauthorized Tool Use.

Showing the 12 highest-severity of 14 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for wordpress-publisher

Audit external network connections
wordpress-publisher sends data to external endpoints. Confirm each destination is expected and authorized, and remove any callback that exfiltrates data. ClawSecure monitors for known exfiltration and C2 endpoints.
Fix ReDoS-prone patterns
wordpress-publisher contains regular expressions vulnerable to catastrophic backtracking (ReDoS). Replace vulnerable patterns, bound input length, and prefer linear-time matching so a crafted input cannot hang the agent.
Eliminate dynamic code execution
wordpress-publisher evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→

Related AI Agent Security Audits

@martian-engineering/lossless-clawScore 25/100openclaw-dashboard-repoScore 25/100openclaw-dashboard-repoScore 25/100@martian-engineering/lossless-clawScore 25/100@martian-engineering/lossless-clawScore 25/100

Scanned on March 27, 2026. wordpress-publisher is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan