maishou is an AI agent skill, created by al-one and published at openclaw/skills. ClawSecure audited maishou across 3 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 80/100 (Safe). The 5 findings concentrate in Unauthorized Tool Use, Social Engineering and Data Exfiltration, including Undeclared Network Access and Skill performs actions not reflected in its description. None were rated high or critical severity.
Is maishou safe?
ClawSecure audited maishou and assigned a security score of 80/100 (Safe), identifying 5 findings across Unauthorized Tool Use and Social Engineering. Review the findings below before installing.
What did ClawSecure find in maishou?
ClawSecure identified 5 findings in maishou, concentrated in Unauthorized Tool Use, Social Engineering and Data Exfiltration. The most severe include Undeclared Network Access and Skill performs actions not reflected in its description.
How was maishou audited?
ClawSecure ran maishou through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 3 files from openclaw/skills.
What does a score of 80 mean?
ClawSecure assigned maishou a security score of 80/100, placing it in the Safe range. Scores of 80 or above qualify for ClawSecure Verified status; the 5 findings detected are lower-severity. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for maishou
ClawSecure detected 5 security findings in maishou, spanning Unauthorized Tool Use, Social Engineering, Data Exfiltration and Permissions Manifest.
- medium · Undeclared Network Access. Unauthorized Tool Use finding detected in
SKILL.md. - medium · Skill performs actions not reflected in its description. Social Engineering finding detected in
SKILL.md. - medium · Suspicious Pattern: aiohttp.ClientSession(. Data Exfiltration finding detected in
scripts/main.py:107. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- info · Missing License Declaration. Policy Violation finding detected in
SKILL.md.
Each finding is expandable in the interactive list below.
3-Layer Audit Protocol
Security Recommendations for maishou
Audit external network connections
Add a config.json permissions manifest
Resolve policy violations
Pin dependencies to exact versions
1.2.3 instead of ^1.2.3) to keep unauthorized code out of your dependency tree. ClawSecure checks every dependency against known CVE databases.Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→How to Secure an MCP Server: The 2026 Guide→Related AI Agent Security Audits
Scanned on March 13, 2026. maishou is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.