← Back to Scanner

c4-nexus-react-ecommerce-assignment Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

c4-nexus-react-ecommerce-assignment is an AI agent skill, created by MatthewBleUK and published at MatthewBleUK/ecommerce-site. ClawSecure audited c4-nexus-react-ecommerce-assignment across 34 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 31/100 (High Risk). The 27 findings concentrate in Supply Chain and Permissions Manifest, including Vulnerability in lodash@4.17.21: lodash vulnerable to Code… and Vulnerability in postcss@8.4.27: PostCSS: Arbitrary file…. 6 were rated high or critical severity.

Is c4-nexus-react-ecommerce-assignment safe?

ClawSecure audited c4-nexus-react-ecommerce-assignment and assigned a security score of 31/100 (High Risk), identifying 27 findings across Supply Chain and Permissions Manifest. Review the findings below before installing.

What did ClawSecure find in c4-nexus-react-ecommerce-assignment?

ClawSecure identified 27 findings in c4-nexus-react-ecommerce-assignment, concentrated in Supply Chain and Permissions Manifest. 6 were rated high or critical severity. The most severe include Vulnerability in lodash@4.17.21: lodash vulnerable to Code… and Vulnerability in postcss@8.4.27: PostCSS: Arbitrary file….

How was c4-nexus-react-ecommerce-assignment audited?

ClawSecure ran c4-nexus-react-ecommerce-assignment through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 34 files from MatthewBleUK/ecommerce-site.

What does a score of 31 mean?

ClawSecure assigned c4-nexus-react-ecommerce-assignment a security score of 31/100, placing it in the High Risk range. This is driven by 27 findings led by Supply Chain that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for c4-nexus-react-ecommerce-assignment

ClawSecure detected 27 security findings in c4-nexus-react-ecommerce-assignment, spanning Supply Chain and Permissions Manifest.

Showing the 12 highest-severity of 27 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for c4-nexus-react-ecommerce-assignment

Update and pin dependencies
c4-nexus-react-ecommerce-assignment depends on packages with supply-chain risk. Pin every dependency to an exact version, update packages with known CVEs to patched releases, and re-audit after each change. ClawSecure checks every dependency against known CVE databases.
Add a config.json permissions manifest
A config.json file declares what an agent component can access: file system, network, shell execution and more. Without it, users have no visibility into what the component can do before installing. This is the single most impactful security improvement for any AI agent skill.
Pin dependencies to exact versions
Unpinned dependencies allow supply-chain attacks where a compromised version is pulled in automatically. Use exact version numbers in package.json (for example 1.2.3 instead of ^1.2.3) to keep unauthorized code out of your dependency tree. ClawSecure checks every dependency against known CVE databases.

Related Security Research

AI Agent Supply Chain Attacks: How Dependencies Become WeaponsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

@martian-engineering/lossless-clawScore 25/100openclaw-dashboard-repoScore 25/100openclaw-dashboard-repoScore 25/100@martian-engineering/lossless-clawScore 25/100@martian-engineering/lossless-clawScore 25/100

Scanned on August 24, 2026. c4-nexus-react-ecommerce-assignment is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan