← Back to Scanner

clauditor Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

clauditor is an AI agent skill, created by apollostreetcompany and published at apollostreetcompany/clauditor. ClawSecure audited clauditor across 36 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 24 findings concentrate in Malicious Code, Unauthorized Tool Use and Code Injection, including Detects potential exposure of sensitive information like API keys,... and Pattern detected: chown root. 20 were rated high or critical severity.

Is clauditor safe?

ClawSecure audited clauditor and assigned a security score of 0/100 (High Risk), identifying 24 findings across Malicious Code and Unauthorized Tool Use. Review the findings below before installing.

What did ClawSecure find in clauditor?

ClawSecure identified 24 findings in clauditor, concentrated in Malicious Code, Unauthorized Tool Use and Code Injection. 20 were rated high or critical severity. The most severe include Detects potential exposure of sensitive information like API keys,... and Pattern detected: chown root.

How was clauditor audited?

ClawSecure ran clauditor through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 36 files from apollostreetcompany/clauditor.

What does a score of 0 mean?

ClawSecure assigned clauditor a security score of 0/100, placing it in the High Risk range. This is driven by 24 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for clauditor

ClawSecure detected 24 security findings in clauditor, spanning Malicious Code, Unauthorized Tool Use, Code Injection and Obfuscation.

Showing the 12 highest-severity of 24 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for clauditor

Audit external network connections
clauditor connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Eliminate dynamic code execution
clauditor evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Review obfuscated or hidden code
clauditor contains obfuscated or hidden content that resists review. Inspect encoded, minified or hidden files to confirm they are not concealing unexpected behavior before installing.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI AgentsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

awesome-openclaw-skillsScore 0/100memUScore 0/100understand-anythingScore 0/10062ac696296b54aadScore 0/1006bc837afc1a86e89Score 0/100

Scanned on May 2, 2026. clauditor is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan