iblipper is an AI agent skill, created by andyed and published at andyed/iblipper. ClawSecure audited iblipper across 36 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 64/100 (Medium Risk). The 26 findings concentrate in Supply Chain, Policy Violation and Obfuscation, including Vulnerability in vite@5.0.8: Vite dev server option `server.fs.deny`... and Only 85% of skill content could be analyzed. 7 of 36 files are opaque.... 1 was rated high or critical severity.
Is iblipper safe?
ClawSecure audited iblipper and assigned a security score of 64/100 (Medium Risk), identifying 26 findings across Supply Chain and Policy Violation. Review the findings below before installing.
What did ClawSecure find in iblipper?
ClawSecure identified 26 findings in iblipper, concentrated in Supply Chain, Policy Violation and Obfuscation. 1 was rated high or critical severity. The most severe include Vulnerability in vite@5.0.8: Vite dev server option `server.fs.deny`... and Only 85% of skill content could be analyzed. 7 of 36 files are opaque....
How was iblipper audited?
ClawSecure ran iblipper through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 36 files from andyed/iblipper.
What does a score of 64 mean?
ClawSecure assigned iblipper a security score of 64/100, placing it in the Medium Risk range. This reflects 26 findings led by Supply Chain that warrant review before production use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for iblipper
ClawSecure detected 26 security findings in iblipper, spanning Supply Chain, Policy Violation, Obfuscation and Permissions Manifest.
- high · Vulnerability in vite@5.0.8: Vite dev server option `server.fs.deny`.... Supply Chain finding detected in
package.json. - medium · Only 85% of skill content could be analyzed. 7 of 36 files are opaque.... Policy Violation finding.
- medium · File 'svelte.config.js' extension (.js) suggests one format but Magika.... Obfuscation finding detected in
svelte.config.js. - medium · File 'vite.config.js' extension (.js) suggests one format but Magika.... Obfuscation finding detected in
vite.config.js. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- low · __pycache__ directory found at src/iblipper/__pycache__/ containing 3.... Policy Violation finding detected in
src/iblipper/__pycache__. - low · Vulnerability in vite@5.0.8: Vite middleware may serve files starting.... Supply Chain finding detected in
package.json. - low · Vulnerability in vite@5.0.8: Vite's `server.fs` settings were not.... Supply Chain finding detected in
package.json. - info · Skill manifest does not include a 'license' field. Specifying a license.... Policy Violation finding detected in
SKILL.md. - moderate · Vulnerability in postcss@8.4.32: PostCSS has XSS via Unescaped </style>.... Supply Chain finding detected in
package.json. - moderate · Vulnerability in svelte@4.2.8: Svelte has a potential mXSS.... Supply Chain finding detected in
package.json. - moderate · Vulnerability in svelte@4.2.8: Svelte SSR attribute spreading includes.... Supply Chain finding detected in
package.json.
Showing the 12 highest-severity of 26 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for iblipper
Update and pin dependencies
Resolve policy violations
Review obfuscated or hidden code
Related Security Research
AI Agent Supply Chain Attacks: How Dependencies Become Weapons→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on May 2, 2026. iblipper is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.