← Back to Scanner

karmabank Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

karmabank is an AI agent skill, created by abdhilabs and published at abdhilabs/karmabank. ClawSecure audited karmabank across 50 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 18 findings concentrate in Supply Chain, Data Exfiltration and Policy Violation, including Only 34% of skill content could be analyzed. 32 of 50 files are opaque... and Pattern detected: fs.readFile(. 11 were rated high or critical severity.

Is karmabank safe?

ClawSecure audited karmabank and assigned a security score of 0/100 (High Risk), identifying 18 findings across Supply Chain and Data Exfiltration. Review the findings below before installing.

What did ClawSecure find in karmabank?

ClawSecure identified 18 findings in karmabank, concentrated in Supply Chain, Data Exfiltration and Policy Violation. 11 were rated high or critical severity. The most severe include Only 34% of skill content could be analyzed. 32 of 50 files are opaque... and Pattern detected: fs.readFile(.

How was karmabank audited?

ClawSecure ran karmabank through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 50 files from abdhilabs/karmabank.

What does a score of 0 mean?

ClawSecure assigned karmabank a security score of 0/100, placing it in the High Risk range. This is driven by 18 findings led by Supply Chain that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for karmabank

ClawSecure detected 18 security findings in karmabank, spanning Supply Chain, Data Exfiltration, Policy Violation and Obfuscation.

Showing the 12 highest-severity of 18 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for karmabank

Update and pin dependencies
karmabank depends on packages with supply-chain risk. Pin every dependency to an exact version, update packages with known CVEs to patched releases, and re-audit after each change. ClawSecure checks every dependency against known CVE databases.
Audit external network connections
karmabank sends data to external endpoints. Confirm each destination is expected and authorized, and remove any callback that exfiltrates data. ClawSecure monitors for known exfiltration and C2 endpoints.
Resolve policy violations
karmabank trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.

Related Security Research

AI Agent Supply Chain Attacks: How Dependencies Become WeaponsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

awesome-openclaw-skillsScore 0/100memUScore 0/100understand-anythingScore 0/10062ac696296b54aadScore 0/1006bc837afc1a86e89Score 0/100

Scanned on May 2, 2026. karmabank is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan