helpscout is an AI agent skill, created by fabiensebban and published at fabiensebban/helpscout. ClawSecure audited helpscout across 15 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 28/100 (High Risk). The 15 findings concentrate in Supply Chain, Data Exfiltration and Policy Violation, including Only 47% of skill content could be analyzed. 8 of 15 files are opaque... and Vulnerability in undici@7.20.0: Undici: Malicious WebSocket 64-bit.... 4 were rated high or critical severity.
Is helpscout safe?
ClawSecure audited helpscout and assigned a security score of 28/100 (High Risk), identifying 15 findings across Supply Chain and Data Exfiltration. Review the findings below before installing.
What did ClawSecure find in helpscout?
ClawSecure identified 15 findings in helpscout, concentrated in Supply Chain, Data Exfiltration and Policy Violation. 4 were rated high or critical severity. The most severe include Only 47% of skill content could be analyzed. 8 of 15 files are opaque... and Vulnerability in undici@7.20.0: Undici: Malicious WebSocket 64-bit....
How was helpscout audited?
ClawSecure ran helpscout through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 15 files from fabiensebban/helpscout.
What does a score of 28 mean?
ClawSecure assigned helpscout a security score of 28/100, placing it in the High Risk range. This is driven by 15 findings led by Supply Chain that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for helpscout
ClawSecure detected 15 security findings in helpscout, spanning Supply Chain, Data Exfiltration, Policy Violation and Obfuscation.
- high · Only 47% of skill content could be analyzed. 8 of 15 files are opaque.... Policy Violation finding.
- high · Vulnerability in undici@7.20.0: Undici: Malicious WebSocket 64-bit.... Supply Chain finding detected in
package.json. - high · Vulnerability in undici@7.20.0: Undici has Unhandled Exception in.... Supply Chain finding detected in
package.json. - high · Vulnerability in undici@7.20.0: Undici has Unbounded Memory Consumption.... Supply Chain finding detected in
package.json. - medium · Pattern detected: fetch(. Data Exfiltration finding detected in
scripts/fetchConversations.js:40. - medium · Pattern detected: fetch(. Data Exfiltration finding detected in
scripts/getToken.js:8. - medium · Pattern detected: fetch(. Data Exfiltration finding detected in
scripts/sendReply.js:42. - medium · Pattern detected: fetch(. Data Exfiltration finding detected in
scripts/sendReply.js:120. - medium · File 'token.test.js' extension (.js) suggests one format but Magika.... Obfuscation finding detected in
tests/token.test.js. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- low · Hidden file found: .clawdhub/lock.json. Hidden files may contain.... Obfuscation finding detected in
.clawdhub/lock.json. - info · Skill manifest does not include a 'license' field. Specifying a license.... Policy Violation finding detected in
SKILL.md.
Showing the 12 highest-severity of 15 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for helpscout
Update and pin dependencies
Audit external network connections
Resolve policy violations
Related Security Research
AI Agent Supply Chain Attacks: How Dependencies Become Weapons→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on May 4, 2026. helpscout is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.