clawslist is an AI agent skill, created by calebwin and published at calebwin/clawslist. ClawSecure audited clawslist across 45 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 91/100 (Safe). The 10 findings concentrate in Supply Chain and Permissions Manifest, including Missing config.json - agent may not be properly configured and Vulnerability in vite@6.0.0: Vite middleware may serve files starting.... None were rated high or critical severity.
Is clawslist safe?
ClawSecure audited clawslist and assigned a security score of 91/100 (Safe), identifying 10 findings across Supply Chain and Permissions Manifest. Review the findings below before installing.
What did ClawSecure find in clawslist?
ClawSecure identified 10 findings in clawslist, concentrated in Supply Chain and Permissions Manifest. The most severe include Missing config.json - agent may not be properly configured and Vulnerability in vite@6.0.0: Vite middleware may serve files starting....
How was clawslist audited?
ClawSecure ran clawslist through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 45 files from calebwin/clawslist.
What does a score of 91 mean?
ClawSecure assigned clawslist a security score of 91/100, placing it in the Safe range. Scores of 80 or above qualify for ClawSecure Verified status; the 10 findings detected are lower-severity. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for clawslist
ClawSecure detected 10 security findings in clawslist, spanning Supply Chain and Permissions Manifest.
- medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- low · Vulnerability in vite@6.0.0: Vite middleware may serve files starting.... Supply Chain finding detected in
package.json. - low · Vulnerability in vite@6.0.0: Vite's `server.fs` settings were not.... Supply Chain finding detected in
package.json. - moderate · Vulnerability in vite@6.0.0: Vite has an `server.fs.deny` bypass with.... Supply Chain finding detected in
package.json. - moderate · Vulnerability in vite@6.0.0: Vite has a `server.fs.deny` bypassed for.... Supply Chain finding detected in
package.json. - moderate · Vulnerability in vite@6.0.0: Vite's server.fs.deny bypassed with /. for.... Supply Chain finding detected in
package.json. - moderate · Vulnerability in vite@6.0.0: vite allows server.fs.deny bypass via.... Supply Chain finding detected in
package.json. - moderate · Vulnerability in vite@6.0.0: Websites were able to send any requests to.... Supply Chain finding detected in
package.json. - moderate · Vulnerability in vite@6.0.0: Vite bypasses server.fs.deny when using.... Supply Chain finding detected in
package.json. - moderate · Vulnerability in vite@6.0.0: Vite allows server.fs.deny to be bypassed.... Supply Chain finding detected in
package.json.
Each finding is expandable in the interactive list below.
3-Layer Audit Protocol
Security Recommendations for clawslist
Update and pin dependencies
Add a config.json permissions manifest
Pin dependencies to exact versions
1.2.3 instead of ^1.2.3) to keep unauthorized code out of your dependency tree. ClawSecure checks every dependency against known CVE databases.Related Security Research
AI Agent Supply Chain Attacks: How Dependencies Become Weapons→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on February 18, 2026. clawslist is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.