← Back to Scanner

qveris Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

qveris is an AI agent skill, created by hqman and published at hqman/qveris. ClawSecure audited qveris across 6 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 61/100 (Medium Risk). The 8 findings concentrate in Command Injection, Code Injection and Unauthorized Tool Use, including Potentially dangerous code pattern detected: curl.*\|.*sh and Potentially dangerous code pattern detected: curl.*\|.*sh. 2 were rated high or critical severity.

Is qveris safe?

ClawSecure audited qveris and assigned a security score of 61/100 (Medium Risk), identifying 8 findings across Command Injection and Code Injection. Review the findings below before installing.

What did ClawSecure find in qveris?

ClawSecure identified 8 findings in qveris, concentrated in Command Injection, Code Injection and Unauthorized Tool Use. 2 were rated high or critical severity. The most severe include Potentially dangerous code pattern detected: curl.*\|.*sh and Potentially dangerous code pattern detected: curl.*\|.*sh.

How was qveris audited?

ClawSecure ran qveris through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 6 files from hqman/qveris.

What does a score of 61 mean?

ClawSecure assigned qveris a security score of 61/100, placing it in the Medium Risk range. This reflects 8 findings led by Command Injection that warrant review before production use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for qveris

ClawSecure detected 8 security findings in qveris, spanning Command Injection, Code Injection, Unauthorized Tool Use and Data Exfiltration.

Each finding is expandable in the interactive list below.

3-Layer Audit Protocol

Security Recommendations for qveris

Harden command execution
qveris constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Eliminate dynamic code execution
qveris evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Audit external network connections
qveris sends data to external endpoints. Confirm each destination is expected and authorized, and remove any callback that exfiltrates data. ClawSecure monitors for known exfiltration and C2 endpoints.

Related Security Research

Why Generic Scanners Fail at AI Agent SecurityUnderstanding Our 3-Layer Audit Protocol

Related AI Agent Security Audits

ui-ux-pro-max-skillScore 75/100GitNexusScore 75/100antigravity-awesome-skillsScore 75/100clawhubScore 75/100openclawScore 55/100

Scanned on May 2, 2026. qveris is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan