← Back to Scanner

cairn-cli Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

cairn-cli is an AI agent skill, created by gregoryehill and published at gregoryehill/cairn-cli. ClawSecure audited cairn-cli across 53 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 29 findings concentrate in Command Injection, Malicious Code and Policy Violation, including Pattern detected: from 'child_process' and Pattern detected: execSync(. 25 were rated high or critical severity.

Is cairn-cli safe?

ClawSecure audited cairn-cli and assigned a security score of 0/100 (High Risk), identifying 29 findings across Command Injection and Malicious Code. Review the findings below before installing.

What did ClawSecure find in cairn-cli?

ClawSecure identified 29 findings in cairn-cli, concentrated in Command Injection, Malicious Code and Policy Violation. 25 were rated high or critical severity. The most severe include Pattern detected: from 'child_process' and Pattern detected: execSync(.

How was cairn-cli audited?

ClawSecure ran cairn-cli through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 53 files from gregoryehill/cairn-cli.

What does a score of 0 mean?

ClawSecure assigned cairn-cli a security score of 0/100, placing it in the High Risk range. This is driven by 29 findings led by Command Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for cairn-cli

ClawSecure detected 29 security findings in cairn-cli, spanning Command Injection, Malicious Code, Policy Violation and Data Exfiltration.

Showing the 12 highest-severity of 29 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for cairn-cli

Harden command execution
cairn-cli constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Audit external network connections
cairn-cli connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Resolve policy violations
cairn-cli trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.

Related Security Research

Why Generic Scanners Fail at AI Agent SecurityUnderstanding Our 3-Layer Audit Protocol

Related AI Agent Security Audits

memUScore 0/100understand-anythingScore 0/10062ac696296b54aadScore 0/1006bc837afc1a86e89Score 0/10062ac696296b54aadScore 0/100

Scanned on May 2, 2026. cairn-cli is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan