yahoo-finance Security Audit Report
yahoo-finance is an AI agent skill, created by ClawHub Skill. ClawSecure audited yahoo-finance across 14 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 14 findings concentrate in Malicious Code, Hardcoded Secrets and Policy Violation, including Credential Access Detected and Credential Access Detected. 9 were rated high or critical severity.
Is yahoo-finance safe?
ClawSecure audited yahoo-finance and assigned a security score of 0/100 (High Risk), identifying 14 findings across Malicious Code and Hardcoded Secrets. Review the findings below before installing.
What did ClawSecure find in yahoo-finance?
ClawSecure identified 14 findings in yahoo-finance, concentrated in Malicious Code, Hardcoded Secrets and Policy Violation. 9 were rated high or critical severity. The most severe include Credential Access Detected and Credential Access Detected.
How was yahoo-finance audited?
ClawSecure ran yahoo-finance through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 14 files.
What does a score of 0 mean?
ClawSecure assigned yahoo-finance a security score of 0/100, placing it in the High Risk range. This is driven by 14 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for yahoo-finance
ClawSecure detected 14 security findings in yahoo-finance, spanning Malicious Code, Hardcoded Secrets, Policy Violation and Supply Chain Attack.
- critical · Credential Access Detected. Hardcoded Secrets finding detected in
scan_logs/cisco/scan.log:8. - critical · Credential Access Detected. Hardcoded Secrets finding detected in
scan_logs/cisco/stdout.json:35. - critical · Credential Access Detected. Hardcoded Secrets finding detected in
scan_logs/cisco/verdict.json:37. - critical · Suspicious domain detected: glot.io (potential data…. Malicious Code finding detected in
SKILL.md. - critical · Suspicious domain detected: glot.io (potential data…. Malicious Code finding detected in
scan.log. - critical · Suspicious domain detected: glot.io (potential data…. Malicious Code finding detected in
stdout.json. - critical · Suspicious domain detected: glot.io (potential data…. Malicious Code finding detected in
verdict.json. - high · An archive is extracted and its contents are then executed.…. Supply Chain Attack finding detected in
SKILL.md:23. - high · An archive is extracted and its contents are then executed.…. Supply Chain Attack finding detected in
SKILL.md:28. - medium · Archive scan_logs/clawsecure/skill.zip is corrupt: File is…. Obfuscation finding detected in
scan_logs/clawsecure/skill.zip. - medium · Archive file found: scan_logs/clawsecure/skill.zip.…. Policy Violation finding detected in
scan_logs/clawsecure/skill.zip. - medium · Binary file 'scan_logs/clawsecure/skill.zip' cannot be…. Policy Violation finding detected in
scan_logs/clawsecure/skill.zip.
Showing the 12 highest-severity of 14 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for yahoo-finance
Audit external network connections
Resolve policy violations
Review obfuscated or hidden code
Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on March 17, 2026. yahoo-finance is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.