← Back to Scanner

arc-sentinel Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

arc-sentinel is an AI agent skill, created by arc-claw-bot and published at arc-claw-bot/arc-sentinel. ClawSecure audited arc-sentinel across 13 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 10/100 (High Risk). The 13 findings concentrate in Command Injection, Code Injection and Policy Violation, including Pattern detected: chmod 777 and Attempts to access sensitive file: .ssh/. 4 were rated high or critical severity.

Is arc-sentinel safe?

ClawSecure audited arc-sentinel and assigned a security score of 10/100 (High Risk), identifying 13 findings across Command Injection and Code Injection. Review the findings below before installing.

What did ClawSecure find in arc-sentinel?

ClawSecure identified 13 findings in arc-sentinel, concentrated in Command Injection, Code Injection and Policy Violation. 4 were rated high or critical severity. The most severe include Pattern detected: chmod 777 and Attempts to access sensitive file: .ssh/.

How was arc-sentinel audited?

ClawSecure ran arc-sentinel through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 13 files from arc-claw-bot/arc-sentinel.

What does a score of 10 mean?

ClawSecure assigned arc-sentinel a security score of 10/100, placing it in the High Risk range. This is driven by 13 findings led by Command Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for arc-sentinel

ClawSecure detected 13 security findings in arc-sentinel, spanning Command Injection, Code Injection, Policy Violation and Unauthorized Tool Use.

Showing the 12 highest-severity of 13 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for arc-sentinel

Harden command execution
arc-sentinel constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Eliminate dynamic code execution
arc-sentinel evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Resolve policy violations
arc-sentinel trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.

Related Security Research

Why Generic Scanners Fail at AI Agent SecurityUnderstanding Our 3-Layer Audit Protocol

Related AI Agent Security Audits

awesome-openclaw-skillsScore 0/100memUScore 0/100fzfScore 25/100understand-anythingScore 0/10062ac696296b54aadScore 0/100

Scanned on May 2, 2026. arc-sentinel is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan