gimhub is an AI agent skill, created by daxiongmao87 and published at openclaw/skills. ClawSecure audited gimhub across 3 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 85/100 (Safe). The 4 findings concentrate in Unauthorized Tool Use, Data Exfiltration and Policy Violation, including Skill code uses network libraries but doesn't declare network... and Script iterates through environment variables in.... None were rated high or critical severity.
Is gimhub safe?
ClawSecure audited gimhub and assigned a security score of 85/100 (Safe), identifying 4 findings across Unauthorized Tool Use and Data Exfiltration. Review the findings below before installing.
What did ClawSecure find in gimhub?
ClawSecure identified 4 findings in gimhub, concentrated in Unauthorized Tool Use, Data Exfiltration and Policy Violation. The most severe include Skill code uses network libraries but doesn't declare network... and Script iterates through environment variables in....
How was gimhub audited?
ClawSecure ran gimhub through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 3 files from openclaw/skills.
What does a score of 85 mean?
ClawSecure assigned gimhub a security score of 85/100, placing it in the Safe range. Scores of 80 or above qualify for ClawSecure Verified status; the 4 findings detected are lower-severity. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for gimhub
ClawSecure detected 4 security findings in gimhub, spanning Unauthorized Tool Use, Data Exfiltration, Policy Violation and Permissions Manifest.
- medium · Skill code uses network libraries but doesn't declare network.... Unauthorized Tool Use finding detected in
/tmp/url-scans/1c0edf7874ab3d19/SKILL.md. - medium · Script iterates through environment variables in.... Data Exfiltration finding detected in
/tmp/url-scans/1c0edf7874ab3d19/scripts/gimhub.py. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- info · Skill manifest does not include a 'license' field. Specifying a license.... Policy Violation finding detected in
SKILL.md.
Each finding is expandable in the interactive list below.
3-Layer Audit Protocol
Security Recommendations for gimhub
Audit external network connections
Resolve policy violations
Add a config.json permissions manifest
Pin dependencies to exact versions
1.2.3 instead of ^1.2.3) to keep unauthorized code out of your dependency tree. ClawSecure checks every dependency against known CVE databases.Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→OWASP ASI Top 10 Explained: The Complete Guide to AI Agent Security Standards→Related AI Agent Security Audits
Scanned on April 1, 2026. gimhub is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.