← Back to Scanner

6bc837afc1a86e89 Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

6bc837afc1a86e89 is a Other skill for the OpenClaw ecosystem, created by NevaMind-AI. ClawSecure audited this skill through our 3-Layer Audit Protocol covering all 10 OWASP ASI Top 10 categories. This skill received a security score of 45/100, indicating significant security concerns that require attention. The audit identified 6 findings, with issues detected across multiple security layers.

3-Layer Audit Protocol

Security Recommendations for 6bc837afc1a86e89

Pin npm dependencies to exact versions
Unpinned dependencies allow supply chain attacks where a compromised package version is automatically pulled into your skill. Use exact version numbers in package.json (e.g., 1.2.3 instead of ^1.2.3) to prevent unauthorized code from entering your dependency tree. ClawSecure's supply chain scanning checks every dependency against known CVE databases.
Add a config.json permissions manifest
A config.json file declares what permissions your OpenClaw skill needs — file system access, network requests, shell execution, and more. Without it, users have no visibility into what your skill can do before installing. Adding a permissions manifest is the single most impactful security improvement for any OpenClaw skill.

Related OpenClaw Security Research

Securing the OpenClaw Ecosystem: Your Complete GuideUnderstanding Our 3-Layer Audit Protocol

Related Other Security Audits

mission-controlScore 33/10085037d8493f24913Score 55/1003d27dc76880146e2Score 45/100c376fd05e09d59c2Score 45/100fe8225736dfe608bScore 45/100

Scanned on June 23, 2026. 6bc837afc1a86e89 is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan