explain-code-for-developer Security Audit Report
explain-code-for-developer is an AI agent skill. ClawSecure audited explain-code-for-developer across 14 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 14 findings concentrate in Command Injection, Code Injection and Policy Violation, including Suspicious Pattern: Function(" and Suspicious Pattern: Function(". 10 were rated high or critical severity.
Is explain-code-for-developer safe?
ClawSecure audited explain-code-for-developer and assigned a security score of 0/100 (High Risk), identifying 14 findings across Command Injection and Code Injection. Review the findings below before installing.
What did ClawSecure find in explain-code-for-developer?
ClawSecure identified 14 findings in explain-code-for-developer, concentrated in Command Injection, Code Injection and Policy Violation. 10 were rated high or critical severity. The most severe include Suspicious Pattern: Function(" and Suspicious Pattern: Function(".
How was explain-code-for-developer audited?
ClawSecure ran explain-code-for-developer through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 14 files.
What does a score of 0 mean?
ClawSecure assigned explain-code-for-developer a security score of 0/100, placing it in the High Risk range. This is driven by 14 findings led by Command Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for explain-code-for-developer
ClawSecure detected 14 security findings in explain-code-for-developer, spanning Command Injection, Code Injection, Policy Violation and Permissions Manifest.
- critical · Suspicious Pattern: Function(". Command Injection finding detected in
runtime/mermaid/mermaid.min.js:2. - critical · Suspicious Pattern: Function(". Command Injection finding detected in
runtime/mermaid/mermaid.min.js:571. - critical · Suspicious Pattern: Function(". Command Injection finding detected in
runtime/mermaid/mermaid.min.js:577. - critical · Suspicious Pattern: Function(". Command Injection finding detected in
runtime/mermaid/mermaid.min.js:1237. - critical · Suspicious Pattern: Function(". Command Injection finding detected in
runtime/mermaid/mermaid.min.js:1296. - high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
mermaid.min.js. - high · Potentially dangerous code pattern detected: wget.*\|.*sh. Code Injection finding detected in
mermaid.min.js. - high · Potentially dangerous code pattern detected: eval\(. Code Injection finding detected in
mermaid.min.js. - high · Potentially dangerous code pattern detected: exec\(. Code Injection finding detected in
mermaid.min.js. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
mermaid.min.js. - medium · Only 80% of skill content could be analyzed. 2 of 14 filesβ¦. Policy Violation finding.
- medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
Showing the 12 highest-severity of 14 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for explain-code-for-developer
Harden command execution
Eliminate dynamic code execution
Resolve policy violations
Related Security Research
Why Generic Scanners Fail at AI Agent SecurityβUnderstanding Our 3-Layer Audit ProtocolβRelated AI Agent Security Audits
Scanned on June 12, 2026. explain-code-for-developer is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.