aitor is an AI agent skill, created by alien69flow and published at alien69flow/aitor. ClawSecure audited aitor across 146 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 61/100 (Medium Risk). The 11 findings concentrate in Supply Chain and Permissions Manifest, including Vulnerability in postcss@8.5.6: PostCSS: Arbitrary file… and Vulnerability in postcss@8.5.6: PostCSS: Path Traversal in…. 3 were rated high or critical severity.
Is aitor safe?
ClawSecure audited aitor and assigned a security score of 61/100 (Medium Risk), identifying 11 findings across Supply Chain and Permissions Manifest. Review the findings below before installing.
What did ClawSecure find in aitor?
ClawSecure identified 11 findings in aitor, concentrated in Supply Chain and Permissions Manifest. 3 were rated high or critical severity. The most severe include Vulnerability in postcss@8.5.6: PostCSS: Arbitrary file… and Vulnerability in postcss@8.5.6: PostCSS: Path Traversal in….
How was aitor audited?
ClawSecure ran aitor through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 146 files from alien69flow/aitor.
What does a score of 61 mean?
ClawSecure assigned aitor a security score of 61/100, placing it in the Medium Risk range. This reflects 11 findings led by Supply Chain that warrant review before production use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for aitor
ClawSecure detected 11 security findings in aitor, spanning Supply Chain and Permissions Manifest.
- high · Vulnerability in postcss@8.5.6: PostCSS: Arbitrary file…. Supply Chain finding detected in
package.json. - high · Vulnerability in postcss@8.5.6: PostCSS: Path Traversal in…. Supply Chain finding detected in
package.json. - high · Vulnerability in vite@5.4.19: vite: `server.fs.deny` bypass…. Supply Chain finding detected in
package.json. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- low · Vulnerability in vite@5.4.19: Vite middleware may serve…. Supply Chain finding detected in
package.json. - low · Vulnerability in vite@5.4.19: Vite's `server.fs` settings…. Supply Chain finding detected in
package.json. - moderate · Vulnerability in postcss@8.5.6: PostCSS: incomplete fix of…. Supply Chain finding detected in
package.json. - moderate · Vulnerability in postcss@8.5.6: PostCSS has XSS via…. Supply Chain finding detected in
package.json. - moderate · Vulnerability in vite@5.4.19: Vite Vulnerable to Path…. Supply Chain finding detected in
package.json. - moderate · Vulnerability in vite@5.4.19: vite allows server.fs.deny…. Supply Chain finding detected in
package.json. - moderate · Vulnerability in vite@5.4.19: launch-editor: NTLMv2 hash…. Supply Chain finding detected in
package.json.
Each finding is expandable in the interactive list below.
3-Layer Audit Protocol
Security Recommendations for aitor
Update and pin dependencies
Add a config.json permissions manifest
Pin dependencies to exact versions
1.2.3 instead of ^1.2.3) to keep unauthorized code out of your dependency tree. ClawSecure checks every dependency against known CVE databases.Related Security Research
AI Agent Supply Chain Attacks: How Dependencies Become Weapons→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on August 12, 2026. aitor is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.