agent-swarm-workflow Security Audit Report
agent-swarm-workflow is an AI agent skill, created by clawdnw and published at openclaw/skills. ClawSecure audited agent-swarm-workflow across 2 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 85/100 (Safe). The 4 findings concentrate in Skill Discovery Abuse, Policy Violation and Permissions Manifest, including Detects protocol manipulation via capability inflation in skill... and Detects protocol manipulation via capability inflation in skill.... None were rated high or critical severity.
Is agent-swarm-workflow safe?
ClawSecure audited agent-swarm-workflow and assigned a security score of 85/100 (Safe), identifying 4 findings across Skill Discovery Abuse and Policy Violation. Review the findings below before installing.
What did ClawSecure find in agent-swarm-workflow?
ClawSecure identified 4 findings in agent-swarm-workflow, concentrated in Skill Discovery Abuse, Policy Violation and Permissions Manifest. The most severe include Detects protocol manipulation via capability inflation in skill... and Detects protocol manipulation via capability inflation in skill....
How was agent-swarm-workflow audited?
ClawSecure ran agent-swarm-workflow through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 2 files from openclaw/skills.
What does a score of 85 mean?
ClawSecure assigned agent-swarm-workflow a security score of 85/100, placing it in the Safe range. Scores of 80 or above qualify for ClawSecure Verified status; the 4 findings detected are lower-severity. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for agent-swarm-workflow
ClawSecure detected 4 security findings in agent-swarm-workflow, spanning Skill Discovery Abuse, Policy Violation and Permissions Manifest.
- medium · Detects protocol manipulation via capability inflation in skill.... Skill Discovery Abuse finding detected in
SKILL.md:222. - medium · Detects protocol manipulation via capability inflation in skill.... Skill Discovery Abuse finding detected in
SKILL.md:370. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- info · Skill manifest does not include a 'license' field. Specifying a license.... Policy Violation finding detected in
SKILL.md.
Each finding is expandable in the interactive list below.
3-Layer Audit Protocol
Security Recommendations for agent-swarm-workflow
Resolve policy violations
Add a config.json permissions manifest
Pin dependencies to exact versions
1.2.3 instead of ^1.2.3) to keep unauthorized code out of your dependency tree. ClawSecure checks every dependency against known CVE databases.Related Security Research
OWASP ASI Top 10 Explained: The Complete Guide to AI Agent Security Standards→Understanding Our 3-Layer Audit Protocol→How to Secure an MCP Server: The 2026 Guide→Related AI Agent Security Audits
Scanned on February 7, 2026. agent-swarm-workflow is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.