← Back to Scanner

smart-router Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

smart-router is an AI agent skill, created by c0nspic0us7urk3r and published at c0nspic0us7urk3r/smart-router. ClawSecure audited smart-router across 27 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 50/100 (Medium Risk). The 6 findings concentrate in Code Injection, Command Injection and Malicious Code, including Code block in references/security.md at line 240 contains… and Attempts to access sensitive file: MEMORY.md. 4 were rated high or critical severity.

Is smart-router safe?

ClawSecure audited smart-router and assigned a security score of 50/100 (Medium Risk), identifying 6 findings across Code Injection and Command Injection. Review the findings below before installing.

What did ClawSecure find in smart-router?

ClawSecure identified 6 findings in smart-router, concentrated in Code Injection, Command Injection and Malicious Code. 4 were rated high or critical severity. The most severe include Code block in references/security.md at line 240 contains… and Attempts to access sensitive file: MEMORY.md.

How was smart-router audited?

ClawSecure ran smart-router through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 27 files from c0nspic0us7urk3r/smart-router.

What does a score of 50 mean?

ClawSecure assigned smart-router a security score of 50/100, placing it in the Medium Risk range. This reflects 6 findings led by Code Injection that warrant review before production use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for smart-router

ClawSecure detected 6 security findings in smart-router, spanning Code Injection, Command Injection, Malicious Code and Permissions Manifest.

Each finding is expandable in the interactive list below.

3-Layer Audit Protocol

Security Recommendations for smart-router

Eliminate dynamic code execution
smart-router evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Harden command execution
smart-router constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Audit external network connections
smart-router connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.

Related Security Research

Why Generic Scanners Fail at AI Agent SecurityBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

keepScore 45/1002fccdde2f962fa7cScore 55/1007caf5d769dee89c3Score 55/1007caf5d769dee89c3Score 55/1002fccdde2f962fa7cScore 55/100

Scanned on June 23, 2026. smart-router is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan