karmabank is an AI agent skill, created by abdhilabs and published at abdhilabs/karmabank. ClawSecure audited karmabank across 50 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 18 findings concentrate in Supply Chain, Data Exfiltration and Policy Violation, including Only 34% of skill content could be analyzed. 32 of 50 files are opaque... and Pattern detected: fs.readFile(. 11 were rated high or critical severity.
Is karmabank safe?
ClawSecure audited karmabank and assigned a security score of 0/100 (High Risk), identifying 18 findings across Supply Chain and Data Exfiltration. Review the findings below before installing.
What did ClawSecure find in karmabank?
ClawSecure identified 18 findings in karmabank, concentrated in Supply Chain, Data Exfiltration and Policy Violation. 11 were rated high or critical severity. The most severe include Only 34% of skill content could be analyzed. 32 of 50 files are opaque... and Pattern detected: fs.readFile(.
How was karmabank audited?
ClawSecure ran karmabank through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 50 files from abdhilabs/karmabank.
What does a score of 0 mean?
ClawSecure assigned karmabank a security score of 0/100, placing it in the High Risk range. This is driven by 18 findings led by Supply Chain that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for karmabank
ClawSecure detected 18 security findings in karmabank, spanning Supply Chain, Data Exfiltration, Policy Violation and Obfuscation.
- high · Only 34% of skill content could be analyzed. 32 of 50 files are opaque.... Policy Violation finding.
- high · Pattern detected: fs.readFile(. Data Exfiltration finding detected in
src/cli/services/ledger.ts:69. - high · Pattern detected: fs.writeFile(. Data Exfiltration finding detected in
src/cli/services/ledger.ts:81. - high · Pattern detected: fs.readFileSync(. Data Exfiltration finding detected in
src/data/storage.ts:75. - high · Pattern detected: fs.writeFileSync(. Data Exfiltration finding detected in
src/data/storage.ts:95. - high · Pattern detected: fs.writeFileSync(. Data Exfiltration finding detected in
tests/ledger.test.ts:24. - high · Vulnerability in axios@1.13.4: Axios is Vulnerable to Denial of Service.... Supply Chain finding detected in
package.json. - high · Vulnerability in node-forge@1.3.3: Forge has a basicConstraints bypass.... Supply Chain finding detected in
package.json. - high · Vulnerability in node-forge@1.3.3: Forge has Denial of Service via.... Supply Chain finding detected in
package.json. - high · Vulnerability in node-forge@1.3.3: Forge has signature forgery in.... Supply Chain finding detected in
package.json. - high · Vulnerability in node-forge@1.3.3: Forge has signature forgery in.... Supply Chain finding detected in
package.json. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
Showing the 12 highest-severity of 18 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for karmabank
Update and pin dependencies
Audit external network connections
Resolve policy violations
Related Security Research
AI Agent Supply Chain Attacks: How Dependencies Become Weapons→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on May 2, 2026. karmabank is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.