← Back to Scanner

aitor Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

aitor is an AI agent skill, created by alien69flow and published at alien69flow/aitor. ClawSecure audited aitor across 146 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 61/100 (Medium Risk). The 11 findings concentrate in Supply Chain and Permissions Manifest, including Vulnerability in postcss@8.5.6: PostCSS: Arbitrary file… and Vulnerability in postcss@8.5.6: PostCSS: Path Traversal in…. 3 were rated high or critical severity.

Is aitor safe?

ClawSecure audited aitor and assigned a security score of 61/100 (Medium Risk), identifying 11 findings across Supply Chain and Permissions Manifest. Review the findings below before installing.

What did ClawSecure find in aitor?

ClawSecure identified 11 findings in aitor, concentrated in Supply Chain and Permissions Manifest. 3 were rated high or critical severity. The most severe include Vulnerability in postcss@8.5.6: PostCSS: Arbitrary file… and Vulnerability in postcss@8.5.6: PostCSS: Path Traversal in….

How was aitor audited?

ClawSecure ran aitor through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 146 files from alien69flow/aitor.

What does a score of 61 mean?

ClawSecure assigned aitor a security score of 61/100, placing it in the Medium Risk range. This reflects 11 findings led by Supply Chain that warrant review before production use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for aitor

ClawSecure detected 11 security findings in aitor, spanning Supply Chain and Permissions Manifest.

Each finding is expandable in the interactive list below.

3-Layer Audit Protocol

Security Recommendations for aitor

Update and pin dependencies
aitor depends on packages with supply-chain risk. Pin every dependency to an exact version, update packages with known CVEs to patched releases, and re-audit after each change. ClawSecure checks every dependency against known CVE databases.
Add a config.json permissions manifest
A config.json file declares what an agent component can access: file system, network, shell execution and more. Without it, users have no visibility into what the component can do before installing. This is the single most impactful security improvement for any AI agent skill.
Pin dependencies to exact versions
Unpinned dependencies allow supply-chain attacks where a compromised version is pulled in automatically. Use exact version numbers in package.json (for example 1.2.3 instead of ^1.2.3) to keep unauthorized code out of your dependency tree. ClawSecure checks every dependency against known CVE databases.

Related Security Research

AI Agent Supply Chain Attacks: How Dependencies Become WeaponsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

remindctlScore 69/100crewAIScore 65/100antigravity-awesome-skillsScore 75/100gstackScore 61/100ui-ux-pro-max-skillScore 55/100

Scanned on August 12, 2026. aitor is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan