← Back to Scanner

clawhub-skill-scanner Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

clawhub-skill-scanner is an AI agent skill, created by amir-ag and published at amir-ag/clawhub-skill-scanner. ClawSecure audited clawhub-skill-scanner across 5 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 31 findings concentrate in Code Injection, Malicious Code and Command Injection, including Suspicious domain detected: glot.io (potential data exfiltration) and Suspicious domain detected: glot.io (potential data exfiltration). 27 were rated high or critical severity.

Is clawhub-skill-scanner safe?

ClawSecure audited clawhub-skill-scanner and assigned a security score of 0/100 (High Risk), identifying 31 findings across Code Injection and Malicious Code. Review the findings below before installing.

What did ClawSecure find in clawhub-skill-scanner?

ClawSecure identified 31 findings in clawhub-skill-scanner, concentrated in Code Injection, Malicious Code and Command Injection. 27 were rated high or critical severity. The most severe include Suspicious domain detected: glot.io (potential data exfiltration) and Suspicious domain detected: glot.io (potential data exfiltration).

How was clawhub-skill-scanner audited?

ClawSecure ran clawhub-skill-scanner through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 5 files from amir-ag/clawhub-skill-scanner.

What does a score of 0 mean?

ClawSecure assigned clawhub-skill-scanner a security score of 0/100, placing it in the High Risk range. This is driven by 31 findings led by Code Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for clawhub-skill-scanner

ClawSecure detected 31 security findings in clawhub-skill-scanner, spanning Code Injection, Malicious Code, Command Injection and Policy Violation.

Showing the 12 highest-severity of 31 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for clawhub-skill-scanner

Eliminate dynamic code execution
clawhub-skill-scanner evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Audit external network connections
clawhub-skill-scanner connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Harden command execution
clawhub-skill-scanner constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.

Related Security Research

Why Generic Scanners Fail at AI Agent SecurityBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

awesome-openclaw-skillsScore 0/100memUScore 0/100understand-anythingScore 0/10062ac696296b54aadScore 0/1006bc837afc1a86e89Score 0/100

Scanned on May 2, 2026. clawhub-skill-scanner is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan