← Back to Scanner

clawshot Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

clawshot is an AI agent skill, created by bardusco and published at openclaw/skills. ClawSecure audited clawshot across 18 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 45/100 (High Risk). The 7 findings concentrate in Unauthorized Tool Use, Code Injection and Policy Violation, including Pattern detected: chmod 700 and Potentially dangerous code pattern detected: curl.*\|.*sh. 3 were rated high or critical severity.

Is clawshot safe?

ClawSecure audited clawshot and assigned a security score of 45/100 (High Risk), identifying 7 findings across Unauthorized Tool Use and Code Injection. Review the findings below before installing.

What did ClawSecure find in clawshot?

ClawSecure identified 7 findings in clawshot, concentrated in Unauthorized Tool Use, Code Injection and Policy Violation. 3 were rated high or critical severity. The most severe include Pattern detected: chmod 700 and Potentially dangerous code pattern detected: curl.*\|.*sh.

How was clawshot audited?

ClawSecure ran clawshot through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 18 files from openclaw/skills.

What does a score of 45 mean?

ClawSecure assigned clawshot a security score of 45/100, placing it in the High Risk range. This is driven by 7 findings led by Unauthorized Tool Use that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for clawshot

ClawSecure detected 7 security findings in clawshot, spanning Unauthorized Tool Use, Code Injection, Policy Violation and Obfuscation.

Each finding is expandable in the interactive list below.

3-Layer Audit Protocol

Security Recommendations for clawshot

Eliminate dynamic code execution
clawshot evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Resolve policy violations
clawshot trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.
Review obfuscated or hidden code
clawshot contains obfuscated or hidden content that resists review. Inspect encoded, minified or hidden files to confirm they are not concealing unexpected behavior before installing.

Related Security Research

Why Generic Scanners Fail at AI Agent SecurityBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

gitlab-cli-skillsScore 55/100@modelcontextprotocol/serversScore 50/100nginx-analyzeScore 60/100nginx-analyzeScore 60/100nginx-analyzeScore 60/100

Scanned on February 7, 2026. clawshot is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan