← Back to Scanner

openclaw-config-validator Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

openclaw-config-validator is an AI agent skill, created by charpup and published at charpup/openclaw-config-validator. ClawSecure audited openclaw-config-validator across 27 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 24 findings concentrate in Data Exfiltration, Command Injection and Policy Violation, including Pattern detected: fs.writeFile( and Pattern detected: fs.readFile(. 16 were rated high or critical severity.

Is openclaw-config-validator safe?

ClawSecure audited openclaw-config-validator and assigned a security score of 0/100 (High Risk), identifying 24 findings across Data Exfiltration and Command Injection. Review the findings below before installing.

What did ClawSecure find in openclaw-config-validator?

ClawSecure identified 24 findings in openclaw-config-validator, concentrated in Data Exfiltration, Command Injection and Policy Violation. 16 were rated high or critical severity. The most severe include Pattern detected: fs.writeFile( and Pattern detected: fs.readFile(.

How was openclaw-config-validator audited?

ClawSecure ran openclaw-config-validator through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 27 files from charpup/openclaw-config-validator.

What does a score of 0 mean?

ClawSecure assigned openclaw-config-validator a security score of 0/100, placing it in the High Risk range. This is driven by 24 findings led by Data Exfiltration that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for openclaw-config-validator

ClawSecure detected 24 security findings in openclaw-config-validator, spanning Data Exfiltration, Command Injection, Policy Violation and Obfuscation.

Showing the 12 highest-severity of 24 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for openclaw-config-validator

Audit external network connections
openclaw-config-validator sends data to external endpoints. Confirm each destination is expected and authorized, and remove any callback that exfiltrates data. ClawSecure monitors for known exfiltration and C2 endpoints.
Harden command execution
openclaw-config-validator constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Resolve policy violations
openclaw-config-validator trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI AgentsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

memUScore 0/10062ac696296b54aadScore 0/1006bc837afc1a86e89Score 0/10062ac696296b54aadScore 0/100openclaw-master-skillsScore 0/100

Scanned on March 11, 2026. openclaw-config-validator is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan