← Back to Scanner

explain-code-for-developer Security Audit Report

πŸ”­ Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

explain-code-for-developer is an AI agent skill. ClawSecure audited explain-code-for-developer across 14 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 14 findings concentrate in Command Injection, Code Injection and Policy Violation, including Suspicious Pattern: Function(" and Suspicious Pattern: Function(". 10 were rated high or critical severity.

Is explain-code-for-developer safe?

ClawSecure audited explain-code-for-developer and assigned a security score of 0/100 (High Risk), identifying 14 findings across Command Injection and Code Injection. Review the findings below before installing.

What did ClawSecure find in explain-code-for-developer?

ClawSecure identified 14 findings in explain-code-for-developer, concentrated in Command Injection, Code Injection and Policy Violation. 10 were rated high or critical severity. The most severe include Suspicious Pattern: Function(" and Suspicious Pattern: Function(".

How was explain-code-for-developer audited?

ClawSecure ran explain-code-for-developer through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 14 files.

What does a score of 0 mean?

ClawSecure assigned explain-code-for-developer a security score of 0/100, placing it in the High Risk range. This is driven by 14 findings led by Command Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for explain-code-for-developer

ClawSecure detected 14 security findings in explain-code-for-developer, spanning Command Injection, Code Injection, Policy Violation and Permissions Manifest.

Showing the 12 highest-severity of 14 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for explain-code-for-developer

Harden command execution
explain-code-for-developer constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Eliminate dynamic code execution
explain-code-for-developer evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Resolve policy violations
explain-code-for-developer trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.

Related Security Research

Why Generic Scanners Fail at AI Agent Security→Understanding Our 3-Layer Audit Protocol→

Related AI Agent Security Audits

byterover-cliScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100

Scanned on June 12, 2026. explain-code-for-developer is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan