cairn-cli is an AI agent skill, created by gregoryehill and published at gregoryehill/cairn-cli. ClawSecure audited cairn-cli across 53 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 29 findings concentrate in Command Injection, Malicious Code and Policy Violation, including Pattern detected: from 'child_process' and Pattern detected: execSync(. 25 were rated high or critical severity.
Is cairn-cli safe?
ClawSecure audited cairn-cli and assigned a security score of 0/100 (High Risk), identifying 29 findings across Command Injection and Malicious Code. Review the findings below before installing.
What did ClawSecure find in cairn-cli?
ClawSecure identified 29 findings in cairn-cli, concentrated in Command Injection, Malicious Code and Policy Violation. 25 were rated high or critical severity. The most severe include Pattern detected: from 'child_process' and Pattern detected: execSync(.
How was cairn-cli audited?
ClawSecure ran cairn-cli through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 53 files from gregoryehill/cairn-cli.
What does a score of 0 mean?
ClawSecure assigned cairn-cli a security score of 0/100, placing it in the High Risk range. This is driven by 29 findings led by Command Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for cairn-cli
ClawSecure detected 29 security findings in cairn-cli, spanning Command Injection, Malicious Code, Policy Violation and Data Exfiltration.
- critical · Pattern detected: from 'child_process'. Command Injection finding detected in
bin/postinstall.js:3. - critical · Pattern detected: execSync(. Command Injection finding detected in
bin/postinstall.js:10. - critical · Pattern detected: execSync(. Command Injection finding detected in
bin/postinstall.js:20. - critical · Pattern detected: execSync(. Command Injection finding detected in
bin/postinstall.js:22. - critical · Pattern detected: from 'child_process'. Command Injection finding detected in
lib/commands/artifact.js:4. - critical · Pattern detected: exec(. Command Injection finding detected in
lib/commands/artifact.js:193. - critical · Pattern detected: from 'child_process'. Command Injection finding detected in
lib/commands/edit.js:4. - critical · Pattern detected: from 'child_process'. Command Injection finding detected in
lib/commands/log.js:4. - critical · Pattern detected: execSync(. Command Injection finding detected in
lib/commands/log.js:16. - critical · Pattern detected: from 'child_process'. Command Injection finding detected in
lib/commands/upgrade.js:1. - critical · Pattern detected: execSync(. Command Injection finding detected in
lib/commands/upgrade.js:26. - critical · Pattern detected: execSync(. Command Injection finding detected in
lib/commands/upgrade.js:56.
Showing the 12 highest-severity of 29 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for cairn-cli
Harden command execution
Audit external network connections
Resolve policy violations
Related Security Research
Why Generic Scanners Fail at AI Agent Security→Understanding Our 3-Layer Audit Protocol→Related AI Agent Security Audits
Scanned on May 2, 2026. cairn-cli is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.