GUI Agent Harness Security Audit Report
GUI Agent Harness is an AI agent skill. ClawSecure audited GUI Agent Harness across 120 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 20 findings concentrate in Code Injection and Permissions Manifest, including Potentially dangerous code pattern detected: exec\( and Potentially dangerous code pattern detected: system\(. 19 were rated high or critical severity.
Is GUI Agent Harness safe?
ClawSecure audited GUI Agent Harness and assigned a security score of 0/100 (High Risk), identifying 20 findings across Code Injection and Permissions Manifest. Review the findings below before installing.
What did ClawSecure find in GUI Agent Harness?
ClawSecure identified 20 findings in GUI Agent Harness, concentrated in Code Injection and Permissions Manifest. 19 were rated high or critical severity. The most severe include Potentially dangerous code pattern detected: exec\( and Potentially dangerous code pattern detected: system\(.
How was GUI Agent Harness audited?
ClawSecure ran GUI Agent Harness through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 120 files.
What does a score of 0 mean?
ClawSecure assigned GUI Agent Harness a security score of 0/100, placing it in the High Risk range. This is driven by 20 findings led by Code Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for GUI Agent Harness
ClawSecure detected 20 security findings in GUI Agent Harness, spanning Code Injection and Permissions Manifest.
- high · Potentially dangerous code pattern detected: exec\(. Code Injection finding detected in
http_remote.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
clipboard.py. - high · Potentially dangerous code pattern detected: exec\(. Code Injection finding detected in
general_action.py. - high · Potentially dangerous code pattern detected: exec\(. Code Injection finding detected in
input.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
input.py. - high · Potentially dangerous code pattern detected: base64.*decode. Code Injection finding detected in
input.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
keyboard.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
window.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
app_memory.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
spreadsheet.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
detector.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
ocr.py.
Showing the 12 highest-severity of 20 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for GUI Agent Harness
Eliminate dynamic code execution
Add a config.json permissions manifest
Pin dependencies to exact versions
1.2.3 instead of ^1.2.3) to keep unauthorized code out of your dependency tree. ClawSecure checks every dependency against known CVE databases.Related Security Research
Why Generic Scanners Fail at AI Agent Security→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on May 25, 2026. GUI Agent Harness is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.