← Back to Scanner

openclaw-security-monitor Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

openclaw-security-monitor is an AI agent skill, created by adibirzu and published at adibirzu/openclaw-security-monitor. ClawSecure audited openclaw-security-monitor across 76 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (Critical). The 81 findings concentrate in Malicious Code, Unauthorized Tool Use and Data Exfiltration, including The find command with -exec executes commands on discovered… and Command injection patterns: bash -i >&. 58 were rated high or critical severity.

Is openclaw-security-monitor safe?

ClawSecure audited openclaw-security-monitor and assigned a security score of 0/100 (Critical), identifying 81 findings across Malicious Code and Unauthorized Tool Use. Review the findings below before installing.

What did ClawSecure find in openclaw-security-monitor?

ClawSecure identified 81 findings in openclaw-security-monitor, concentrated in Malicious Code, Unauthorized Tool Use and Data Exfiltration. 58 were rated high or critical severity. The most severe include The find command with -exec executes commands on discovered… and Command injection patterns: bash -i >&.

How was openclaw-security-monitor audited?

ClawSecure ran openclaw-security-monitor through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 76 files from adibirzu/openclaw-security-monitor.

What does a score of 0 mean?

ClawSecure assigned openclaw-security-monitor a security score of 0/100, placing it in the Critical range. This is driven by 81 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for openclaw-security-monitor

ClawSecure detected 81 security findings in openclaw-security-monitor, spanning Malicious Code, Unauthorized Tool Use, Data Exfiltration and Code Injection.

Showing the 12 highest-severity of 81 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for openclaw-security-monitor

Audit external network connections
openclaw-security-monitor connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Eliminate dynamic code execution
openclaw-security-monitor evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Harden command execution
openclaw-security-monitor constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→

Related AI Agent Security Audits

CowAgentScore 0/100AI-Agent-Risk-EvaluationScore 0/100self-improvementScore 0/100GUI Agent HarnessScore 0/100braindbScore 0/100

Scanned on September 19, 2026. openclaw-security-monitor is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan