← Back to Scanner

thepopebot Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

thepopebot is an AI agent skill, created by Stephen Pope. ClawSecure audited thepopebot across 514 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 51/100 (Warning). The 9 findings concentrate in Supply Chain, Malicious Code and Code Injection, including Attempts to access sensitive file: SOUL.md and Potentially dangerous code pattern detected: exec\(. 4 were rated high or critical severity.

Is thepopebot safe?

ClawSecure audited thepopebot and assigned a security score of 51/100 (Warning), identifying 9 findings across Supply Chain and Malicious Code. Review the findings below before installing.

What did ClawSecure find in thepopebot?

ClawSecure identified 9 findings in thepopebot, concentrated in Supply Chain, Malicious Code and Code Injection. 4 were rated high or critical severity. The most severe include Attempts to access sensitive file: SOUL.md and Potentially dangerous code pattern detected: exec\(.

How was thepopebot audited?

ClawSecure ran thepopebot through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 514 files.

What does a score of 51 mean?

ClawSecure assigned thepopebot a security score of 51/100, placing it in the Warning range. This is driven by 9 findings led by Supply Chain that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for thepopebot

ClawSecure detected 9 security findings in thepopebot, spanning Supply Chain, Malicious Code, Code Injection and Permissions Manifest.

Each finding is expandable in the interactive list below.

3-Layer Audit Protocol

Security Recommendations for thepopebot

Update and pin dependencies
thepopebot depends on packages with supply-chain risk. Pin every dependency to an exact version, update packages with known CVEs to patched releases, and re-audit after each change. ClawSecure checks every dependency against known CVE databases.
Audit external network connections
thepopebot connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Eliminate dynamic code execution
thepopebot evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.

Related Security Research

AI Agent Supply Chain Attacks: How Dependencies Become Weapons→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→

Related AI Agent Security Audits

@modelcontextprotocol/serversScore 50/100gitlab-cli-skillsScore 55/100@fazaboa/opencode-auto-continueScore 55/100xlsxScore 63/100skill-creatorScore 65/100

Scanned on September 27, 2026. thepopebot is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan