openclaw-marshal-pro Security Audit Report
openclaw-marshal-pro is an AI agent skill, created by atlaspa and published at openclaw/skills. ClawSecure audited openclaw-marshal-pro across 4 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 25 findings concentrate in Unauthorized Tool Use, Command Injection and Code Injection, including Pattern detected: eval( and Pattern detected: exec(. 23 were rated high or critical severity.
Is openclaw-marshal-pro safe?
ClawSecure audited openclaw-marshal-pro and assigned a security score of 0/100 (High Risk), identifying 25 findings across Unauthorized Tool Use and Command Injection. Review the findings below before installing.
What did ClawSecure find in openclaw-marshal-pro?
ClawSecure identified 25 findings in openclaw-marshal-pro, concentrated in Unauthorized Tool Use, Command Injection and Code Injection. 23 were rated high or critical severity. The most severe include Pattern detected: eval( and Pattern detected: exec(.
How was openclaw-marshal-pro audited?
ClawSecure ran openclaw-marshal-pro through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 4 files from openclaw/skills.
What does a score of 0 mean?
ClawSecure assigned openclaw-marshal-pro a security score of 0/100, placing it in the High Risk range. This is driven by 25 findings led by Unauthorized Tool Use that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for openclaw-marshal-pro
ClawSecure detected 25 security findings in openclaw-marshal-pro, spanning Unauthorized Tool Use, Command Injection, Code Injection and Policy Violation.
- critical · Pattern detected: eval(. Command Injection finding detected in
scripts/marshal.py:78. - critical · Pattern detected: exec(. Command Injection finding detected in
scripts/marshal.py:79. - critical · Pattern detected: compile(. Command Injection finding detected in
scripts/marshal.py:84. - critical · Pattern detected: eval(. Command Injection finding detected in
scripts/marshal.py:739. - critical · Pattern detected: exec(. Command Injection finding detected in
scripts/marshal.py:739. - critical · Pattern detected: compile(. Command Injection finding detected in
scripts/marshal.py:749. - critical · Pattern detected: eval(. Command Injection finding detected in
scripts/marshal.py:1468. - high · Detects system manipulation, privilege escalation, and destructive file.... Unauthorized Tool Use finding detected in
SKILL.md:128. - high · Detects system manipulation, privilege escalation, and destructive file.... Unauthorized Tool Use finding detected in
scripts/marshal.py:119. - high · Detects system manipulation, privilege escalation, and destructive file.... Unauthorized Tool Use finding detected in
scripts/marshal.py:153. - high · Detects system manipulation, privilege escalation, and destructive file.... Unauthorized Tool Use finding detected in
scripts/marshal.py:182. - high · Detects system manipulation, privilege escalation, and destructive file.... Unauthorized Tool Use finding detected in
scripts/marshal.py:215.
Showing the 12 highest-severity of 25 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for openclaw-marshal-pro
Harden command execution
Eliminate dynamic code execution
Resolve policy violations
Related Security Research
Why Generic Scanners Fail at AI Agent Security→Understanding Our 3-Layer Audit Protocol→Related AI Agent Security Audits
Scanned on February 7, 2026. openclaw-marshal-pro is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.