← Back to Scanner

agent-council Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

agent-council is an AI agent skill, created by itsahedge and published at itsahedge/agent-council. ClawSecure audited agent-council across 14 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 40/100 (High Risk). The 9 findings concentrate in Malicious Code, Command Injection and Policy Violation, including Attempts to access sensitive file: SOUL.md and Attempts to access sensitive file: SOUL.md. 4 were rated high or critical severity.

Is agent-council safe?

ClawSecure audited agent-council and assigned a security score of 40/100 (High Risk), identifying 9 findings across Malicious Code and Command Injection. Review the findings below before installing.

What did ClawSecure find in agent-council?

ClawSecure identified 9 findings in agent-council, concentrated in Malicious Code, Command Injection and Policy Violation. 4 were rated high or critical severity. The most severe include Attempts to access sensitive file: SOUL.md and Attempts to access sensitive file: SOUL.md.

How was agent-council audited?

ClawSecure ran agent-council through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 14 files from itsahedge/agent-council.

What does a score of 40 mean?

ClawSecure assigned agent-council a security score of 40/100, placing it in the High Risk range. This is driven by 9 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for agent-council

ClawSecure detected 9 security findings in agent-council, spanning Malicious Code, Command Injection, Policy Violation and Permissions Manifest.

Each finding is expandable in the interactive list below.

3-Layer Audit Protocol

Security Recommendations for agent-council

Audit external network connections
agent-council connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Harden command execution
agent-council constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Resolve policy violations
agent-council trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI AgentsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

keepScore 45/100gnoScore 45/100ClawSecScore 45/100claude-memScore 35/100openclawScore 55/100

Scanned on May 3, 2026. agent-council is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan