yahoo-finance-m16op Security Audit Report
yahoo-finance-m16op is an AI agent skill, created by ClawHub Skill. ClawSecure audited yahoo-finance-m16op across 14 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 16 findings concentrate in Malicious Code, Command Injection and Policy Violation, including Suspicious domain detected: glot.io (potential data… and Suspicious domain detected: glot.io (potential data…. 11 were rated high or critical severity.
Is yahoo-finance-m16op safe?
ClawSecure audited yahoo-finance-m16op and assigned a security score of 0/100 (High Risk), identifying 16 findings across Malicious Code and Command Injection. Review the findings below before installing.
What did ClawSecure find in yahoo-finance-m16op?
ClawSecure identified 16 findings in yahoo-finance-m16op, concentrated in Malicious Code, Command Injection and Policy Violation. 11 were rated high or critical severity. The most severe include Suspicious domain detected: glot.io (potential data… and Suspicious domain detected: glot.io (potential data….
How was yahoo-finance-m16op audited?
ClawSecure ran yahoo-finance-m16op through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 14 files.
What does a score of 0 mean?
ClawSecure assigned yahoo-finance-m16op a security score of 0/100, placing it in the High Risk range. This is driven by 16 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for yahoo-finance-m16op
ClawSecure detected 16 security findings in yahoo-finance-m16op, spanning Malicious Code, Command Injection, Policy Violation and Code Injection.
- critical · Suspicious domain detected: glot.io (potential data…. Malicious Code finding detected in
SKILL.md. - critical · Suspicious domain detected: glot.io (potential data…. Malicious Code finding detected in
scan.log. - critical · Suspicious domain detected: glot.io (potential data…. Malicious Code finding detected in
stdout.json. - critical · Suspicious domain detected: glot.io (potential data…. Malicious Code finding detected in
verdict.json. - critical · Suspicious domain detected: glot.io (potential data…. Malicious Code finding detected in
stdout.json. - critical · Suspicious domain detected: glot.io (potential data…. Malicious Code finding detected in
verdict.json. - high · Pipeline downloads data from the network and executes it:…. Command Injection finding detected in
SKILL.md:1. - high · Pipeline downloads data from the network and executes it:…. Command Injection finding detected in
scan_logs/cisco/scan.log:1. - high · Pipeline downloads data from the network and executes it:…. Command Injection finding detected in
scan_logs/cisco/stdout.json:1. - high · Pipeline downloads data from the network and executes it:…. Command Injection finding detected in
scan_logs/cisco/verdict.json:1. - high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
SKILL.md. - medium · Archive scan_logs/clawsecure/skill.zip is corrupt: File is…. Obfuscation finding detected in
scan_logs/clawsecure/skill.zip.
Showing the 12 highest-severity of 16 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for yahoo-finance-m16op
Audit external network connections
Harden command execution
Resolve policy violations
Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on March 17, 2026. yahoo-finance-m16op is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.