HomeScanBlogRegistryMarketplace🔍 Scan a Skill
← Back to Scanner

VoxLog Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

VoxLog is a Other skill for the OpenClaw ecosystem, created by lanceterrill. ClawSecure audited this skill through our 3-Layer Audit Protocol covering all 10 OWASP ASI Top 10 categories. This skill received a security score of 100/100, qualifying for ClawSecure Verified status. No security vulnerabilities were detected across any of the three audit layers.

What does a score of 100 mean?

A security score of 100/100 places this skill in the Safe range. Skills scoring 80 or above qualify for ClawSecure Verified status, indicating they passed our comprehensive audit with minimal or no security concerns. ClawSecure calculates scores using a weighted deduction model: critical findings deduct 20 points, high-severity findings deduct 10, medium-severity 5, and low-severity 2. A perfect score of 100 means no findings were detected across all three audit layers.

Security Considerations for Other Skills

Agent skills that don't fall into a specific category still benefit from core security practices. The most impactful improvement is adding a config.json permissions manifest — 99.3% of scanned skills ship without one, leaving users with no visibility into what capabilities the skill requests before installation. Even when no vulnerabilities are detected, ongoing monitoring is important — ClawSecure's Watchtower system continuously tracks code changes and re-verifies skills as they evolve.

3-Layer Audit Protocol

OWASP ASI Top 10 Coverage

This audit checked VoxLog against all 10 categories of the OWASP Agentic Security Initiative (ASI) Top 10 framework: Agent Goal Hijack (ASI01), Tool Misuse & Exploitation (ASI02), Identity & Privilege Abuse (ASI03), Agentic Supply Chain Vulnerabilities (ASI04), Unexpected Code Execution (ASI05), Memory & Context Poisoning (ASI06), Insecure Inter-Agent Communication (ASI07), Cascading Failures (ASI08), Human-Agent Trust Exploitation (ASI09), and Rogue Agents (ASI10). No findings were detected in any category.

Security Recommendations for VoxLog

Pin npm dependencies to exact versions
Unpinned dependencies allow supply chain attacks where a compromised package version is automatically pulled into your skill. Use exact version numbers in package.json (e.g., 1.2.3 instead of ^1.2.3) to prevent unauthorized code from entering your dependency tree. ClawSecure's supply chain scanning checks every dependency against known CVE databases.
Add a config.json permissions manifest
A config.json file declares what permissions your OpenClaw skill needs — file system access, network requests, shell execution, and more. Without it, users have no visibility into what your skill can do before installing. Adding a permissions manifest is the single most impactful security improvement for any OpenClaw skill.

Related OpenClaw Security Research

How to Verify Any OpenClaw Skill in 30 SecondsSecuring the OpenClaw Ecosystem: Your Complete Guide

Related Other Security Audits

c376fd05e09d59c2Score 85/10082e91eab3f7b3025Score 85/100b2e107e8f7224f2aScore 85/100624aee5f17bf59b1Score 95/1008ce21d32f8ead424Score 95/100

Scanned on April 7, 2026. VoxLog is one of 2,890+ agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

🔍 Scan Another Agent