wheels-router Security Audit Report
wheels-router is an AI agent skill, created by anscg and published at openclaw/skills. ClawSecure audited wheels-router across 2 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 65/100 (Medium Risk). The 4 findings concentrate in Skill Discovery Abuse, Hardcoded Secrets and Permissions Manifest, including Detects potential exposure of sensitive information like API keys,... and Detects protocol manipulation via capability inflation in skill.... 1 was rated high or critical severity.
Is wheels-router safe?
ClawSecure audited wheels-router and assigned a security score of 65/100 (Medium Risk), identifying 4 findings across Skill Discovery Abuse and Hardcoded Secrets. Review the findings below before installing.
What did ClawSecure find in wheels-router?
ClawSecure identified 4 findings in wheels-router, concentrated in Skill Discovery Abuse, Hardcoded Secrets and Permissions Manifest. 1 was rated high or critical severity. The most severe include Detects potential exposure of sensitive information like API keys,... and Detects protocol manipulation via capability inflation in skill....
How was wheels-router audited?
ClawSecure ran wheels-router through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 2 files from openclaw/skills.
What does a score of 65 mean?
ClawSecure assigned wheels-router a security score of 65/100, placing it in the Medium Risk range. This reflects 4 findings led by Skill Discovery Abuse that warrant review before production use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for wheels-router
ClawSecure detected 4 security findings in wheels-router, spanning Skill Discovery Abuse, Hardcoded Secrets and Permissions Manifest.
- critical · Detects potential exposure of sensitive information like API keys,.... Hardcoded Secrets finding detected in
SKILL.md:57. - medium · Detects protocol manipulation via capability inflation in skill.... Skill Discovery Abuse finding detected in
SKILL.md:85. - medium · Detects protocol manipulation via capability inflation in skill.... Skill Discovery Abuse finding detected in
SKILL.md:85. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
Each finding is expandable in the interactive list below.
3-Layer Audit Protocol
Security Recommendations for wheels-router
Add a config.json permissions manifest
Pin dependencies to exact versions
1.2.3 instead of ^1.2.3) to keep unauthorized code out of your dependency tree. ClawSecure checks every dependency against known CVE databases.Related Security Research
How to Secure an MCP Server: The 2026 Guide→What Is MCP Security? Model Context Protocol Explained→AI Agent Security: The Complete 2026 Guide→Related AI Agent Security Audits
Scanned on February 7, 2026. wheels-router is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.