clauditor is an AI agent skill, created by apollostreetcompany and published at apollostreetcompany/clauditor. ClawSecure audited clauditor across 36 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 24 findings concentrate in Malicious Code, Unauthorized Tool Use and Code Injection, including Detects potential exposure of sensitive information like API keys,... and Pattern detected: chown root. 20 were rated high or critical severity.
Is clauditor safe?
ClawSecure audited clauditor and assigned a security score of 0/100 (High Risk), identifying 24 findings across Malicious Code and Unauthorized Tool Use. Review the findings below before installing.
What did ClawSecure find in clauditor?
ClawSecure identified 24 findings in clauditor, concentrated in Malicious Code, Unauthorized Tool Use and Code Injection. 20 were rated high or critical severity. The most severe include Detects potential exposure of sensitive information like API keys,... and Pattern detected: chown root.
How was clauditor audited?
ClawSecure ran clauditor through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 36 files from apollostreetcompany/clauditor.
What does a score of 0 mean?
ClawSecure assigned clauditor a security score of 0/100, placing it in the High Risk range. This is driven by 24 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for clauditor
ClawSecure detected 24 security findings in clauditor, spanning Malicious Code, Unauthorized Tool Use, Code Injection and Obfuscation.
- critical · Detects potential exposure of sensitive information like API keys,.... Hardcoded Secrets finding detected in
crates/detector/src/sensitive.rs:11. - critical · Pattern detected: chown root. Unauthorized Tool Use finding detected in
test-fix.sh:13. - critical · Pattern detected: chown root. Unauthorized Tool Use finding detected in
wizard/install.sh:86. - critical · Pattern detected: sudo systemctl. Unauthorized Tool Use finding detected in
wizard/install.sh:144. - critical · Pattern detected: sudo systemctl. Unauthorized Tool Use finding detected in
wizard/install.sh:156. - critical · Pattern detected: chown root. Unauthorized Tool Use finding detected in
wizard/wizard.sh:188. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
ANOMALY_DETECTION_PLAN.md. - high · Attempts to access sensitive file: .ssh/. Malicious Code finding detected in
ANOMALY_DETECTION_PLAN.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
LIGHTWEIGHT_DEFENSE_PLAN.md. - high · Attempts to access sensitive file: .ssh/. Malicious Code finding detected in
LIGHTWEIGHT_DEFENSE_PLAN.md. - high · Attempts to access sensitive file: .ssh/. Malicious Code finding detected in
lib.rs. - high · Attempts to access sensitive file: .ssh/. Malicious Code finding detected in
lib.rs.
Showing the 12 highest-severity of 24 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for clauditor
Audit external network connections
Eliminate dynamic code execution
Review obfuscated or hidden code
Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on May 2, 2026. clauditor is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.