← Back to Scanner

wordpress-publishing-skill-for-claude Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

wordpress-publishing-skill-for-claude is an AI agent skill, created by asif2bd and published at asif2bd/wordpress-publishing-skill-for-claude. ClawSecure audited wordpress-publishing-skill-for-claude across 22 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 30/100 (High Risk). The 14 findings concentrate in Data Exfiltration, ReDoS and Unauthorized Tool Use, including Potentially dangerous code pattern detected: base64.*decode and Skill code uses network libraries but doesn't declare network.... 1 was rated high or critical severity.

Is wordpress-publishing-skill-for-claude safe?

ClawSecure audited wordpress-publishing-skill-for-claude and assigned a security score of 30/100 (High Risk), identifying 14 findings across Data Exfiltration and ReDoS. Review the findings below before installing.

What did ClawSecure find in wordpress-publishing-skill-for-claude?

ClawSecure identified 14 findings in wordpress-publishing-skill-for-claude, concentrated in Data Exfiltration, ReDoS and Unauthorized Tool Use. 1 was rated high or critical severity. The most severe include Potentially dangerous code pattern detected: base64.*decode and Skill code uses network libraries but doesn't declare network....

How was wordpress-publishing-skill-for-claude audited?

ClawSecure ran wordpress-publishing-skill-for-claude through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 22 files from asif2bd/wordpress-publishing-skill-for-claude.

What does a score of 30 mean?

ClawSecure assigned wordpress-publishing-skill-for-claude a security score of 30/100, placing it in the High Risk range. This is driven by 14 findings led by Data Exfiltration that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for wordpress-publishing-skill-for-claude

ClawSecure detected 14 security findings in wordpress-publishing-skill-for-claude, spanning Data Exfiltration, ReDoS, Unauthorized Tool Use and Social Engineering.

Showing the 12 highest-severity of 14 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for wordpress-publishing-skill-for-claude

Audit external network connections
wordpress-publishing-skill-for-claude sends data to external endpoints. Confirm each destination is expected and authorized, and remove any callback that exfiltrates data. ClawSecure monitors for known exfiltration and C2 endpoints.
Fix ReDoS-prone patterns
wordpress-publishing-skill-for-claude contains regular expressions vulnerable to catastrophic backtracking (ReDoS). Replace vulnerable patterns, bound input length, and prefer linear-time matching so a crafted input cannot hang the agent.
Resolve policy violations
wordpress-publishing-skill-for-claude trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI AgentsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

fzfScore 25/100open-webuiScore 35/100gnoScore 45/100keepScore 45/100claude-memScore 35/100

Scanned on May 2, 2026. wordpress-publishing-skill-for-claude is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan