ui-ux-pro-max-skill Security Audit Report
ui-ux-pro-max-skill is an AI agent skill, created by nextlevelbuilder and published at nextlevelbuilder/ui-ux-pro-max-skill. ClawSecure audited ui-ux-pro-max-skill across 74 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 55/100 (Medium Risk). The 7 findings concentrate in ReDoS, Code Injection and Permissions Manifest, including Potentially dangerous code pattern detected: system\( and Potentially dangerous code pattern detected: system\(. 2 were rated high or critical severity.
Is ui-ux-pro-max-skill safe?
ClawSecure audited ui-ux-pro-max-skill and assigned a security score of 55/100 (Medium Risk), identifying 7 findings across ReDoS and Code Injection. Review the findings below before installing.
What did ClawSecure find in ui-ux-pro-max-skill?
ClawSecure identified 7 findings in ui-ux-pro-max-skill, concentrated in ReDoS, Code Injection and Permissions Manifest. 2 were rated high or critical severity. The most severe include Potentially dangerous code pattern detected: system\( and Potentially dangerous code pattern detected: system\(.
How was ui-ux-pro-max-skill audited?
ClawSecure ran ui-ux-pro-max-skill through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 74 files from nextlevelbuilder/ui-ux-pro-max-skill.
What does a score of 55 mean?
ClawSecure assigned ui-ux-pro-max-skill a security score of 55/100, placing it in the Medium Risk range. This reflects 7 findings led by ReDoS that warrant review before production use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for ui-ux-pro-max-skill
ClawSecure detected 7 security findings in ui-ux-pro-max-skill, spanning ReDoS, Code Injection and Permissions Manifest.
- high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
design_system.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
search.py. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- medium · ReDoS vulnerability: Nested quantifiers (potential…. ReDoS finding detected in
reasoning_contract.py:48. - medium · ReDoS vulnerability: Python regex with nested quantifiers —…. ReDoS finding detected in
reasoning_contract.py:48. - medium · ReDoS vulnerability: Nested quantifiers (potential…. ReDoS finding detected in
validate_data.py:41. - medium · ReDoS vulnerability: Python regex with nested quantifiers —…. ReDoS finding detected in
validate_data.py:41.
Each finding is expandable in the interactive list below.
3-Layer Audit Protocol
Security Recommendations for ui-ux-pro-max-skill
Fix ReDoS-prone patterns
Eliminate dynamic code execution
Add a config.json permissions manifest
Related Security Research
Why Generic Scanners Fail at AI Agent Security→Understanding Our 3-Layer Audit Protocol→Related AI Agent Security Audits
Scanned on August 14, 2026. ui-ux-pro-max-skill is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.