← Back to Scanner

openclaw-security-monitor Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

openclaw-security-monitor is an AI agent skill, created by adibirzu and published at openclaw/skills. ClawSecure audited openclaw-security-monitor across 67 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 76 findings concentrate in Malicious Code, Unauthorized Tool Use and Command Injection, including Detects command injection patterns in agent skills: shell operators,... and Detects command injection patterns in agent skills: shell operators,.... 58 were rated high or critical severity.

Is openclaw-security-monitor safe?

ClawSecure audited openclaw-security-monitor and assigned a security score of 0/100 (High Risk), identifying 76 findings across Malicious Code and Unauthorized Tool Use. Review the findings below before installing.

What did ClawSecure find in openclaw-security-monitor?

ClawSecure identified 76 findings in openclaw-security-monitor, concentrated in Malicious Code, Unauthorized Tool Use and Command Injection. 58 were rated high or critical severity. The most severe include Detects command injection patterns in agent skills: shell operators,... and Detects command injection patterns in agent skills: shell operators,....

How was openclaw-security-monitor audited?

ClawSecure ran openclaw-security-monitor through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 67 files from openclaw/skills.

What does a score of 0 mean?

ClawSecure assigned openclaw-security-monitor a security score of 0/100, placing it in the High Risk range. This is driven by 76 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for openclaw-security-monitor

ClawSecure detected 76 security findings in openclaw-security-monitor, spanning Malicious Code, Unauthorized Tool Use, Command Injection and Code Injection.

Showing the 12 highest-severity of 76 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for openclaw-security-monitor

Audit external network connections
openclaw-security-monitor connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Harden command execution
openclaw-security-monitor constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Eliminate dynamic code execution
openclaw-security-monitor evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI AgentsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

memUScore 0/10062ac696296b54aadScore 0/1006bc837afc1a86e89Score 0/10062ac696296b54aadScore 0/100openclaw-master-skillsScore 0/100

Scanned on April 24, 2026. openclaw-security-monitor is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan