← Back to Scanner

claude-to-im Security Audit Report

πŸ”­ Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

claude-to-im is an AI agent skill, created by op7418 and published at op7418/claude-to-im-skill. ClawSecure audited claude-to-im across 38 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 19 findings concentrate in Data Exfiltration, Command Injection and Policy Violation, including Suspicious Pattern: Function(' and Suspicious Pattern: execSync(. 14 were rated high or critical severity.

Is claude-to-im safe?

ClawSecure audited claude-to-im and assigned a security score of 0/100 (High Risk), identifying 19 findings across Data Exfiltration and Command Injection. Review the findings below before installing.

What did ClawSecure find in claude-to-im?

ClawSecure identified 19 findings in claude-to-im, concentrated in Data Exfiltration, Command Injection and Policy Violation. 14 were rated high or critical severity. The most severe include Suspicious Pattern: Function(' and Suspicious Pattern: execSync(.

How was claude-to-im audited?

ClawSecure ran claude-to-im through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 38 files from op7418/claude-to-im-skill.

What does a score of 0 mean?

ClawSecure assigned claude-to-im a security score of 0/100, placing it in the High Risk range. This is driven by 19 findings led by Data Exfiltration that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for claude-to-im

ClawSecure detected 19 security findings in claude-to-im, spanning Data Exfiltration, Command Injection, Policy Violation and Permissions Manifest.

Showing the 12 highest-severity of 19 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for claude-to-im

Audit external network connections
claude-to-im sends data to external endpoints. Confirm each destination is expected and authorized, and remove any callback that exfiltrates data. ClawSecure monitors for known exfiltration and C2 endpoints.
Harden command execution
claude-to-im constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Resolve policy violations
claude-to-im trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→

Related AI Agent Security Audits

understand-anythingScore 0/100memUScore 0/10062ac696296b54aadScore 0/1006bc837afc1a86e89Score 0/10062ac696296b54aadScore 0/100

Scanned on March 16, 2026. claude-to-im is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan